React2Shell: Critical Remote Code Execution Threat Hits Reactjs and Nextjs

Listen to this Post

Featured Image
React.js, the popular JavaScript library powering interactive user interfaces for millions of web applications, has been hit by a critical security vulnerability. Disclosed by researcher Lachlan Davidson on November 29, 2025, this flaw—tracked as CVE-2025-55182 and dubbed React2Shell—poses a severe risk to server-side implementations of React.js. With a maximum CVSS score of 10.0, the vulnerability allows attackers to execute arbitrary code remotely, potentially taking full control of affected servers. Next.js, another widely used JavaScript framework built on React, was also reported as vulnerable, though the US National Vulnerability Database (NVD) later recognized the issue as a duplicate of CVE-2025-55182.

The React2Shell vulnerability exploits core deserialization logic in the frameworks, meaning it’s not limited to rare or obscure configurations. Reports indicate that default configurations of React and Next.js are fully exploitable, with JFrog researchers citing nearly a 100% success rate in standard setups. The flaw affects React Server Function endpoints and Next.js applications using the default App Router configuration. Security experts warn that a single malicious HTTP request could trigger unauthenticated remote code execution, exposing sensitive data and compromising entire server environments.

Since the public disclosure, proof-of-concept exploits have emerged online. OX Security confirmed that hackers have published working PoCs, making this threat actively exploitable in real-world scenarios. Complicating matters, fake PoCs circulating on GitHub may contain malicious code, so verification is critical before testing. Immediate remediation requires updating vulnerable packages to patched versions. React 19.0.1, 19.1.2, and 19.2.1 address the flaw, while Next.js developers may need to adjust App Router configurations or revert to the Pages Router if feasible.

Summary of React2Shell Vulnerability

React2Shell represents one of the most serious security risks to web applications in recent years due to its ease of exploitation and the sheer ubiquity of the affected frameworks. Unlike many supply chain vulnerabilities, which rely on specific niche configurations, this flaw targets the core deserialization logic, making nearly all default installations susceptible. The criticality is underscored by its CVSS rating of 10.0, signaling maximum risk.

The timeline began with Lachlan Davidson’s disclosure to Meta on November 29, followed by a separate advisory from the Next.js team. Although Next.js attempted to track a separate CVE (CVE-2025-66478), the NVD merged it under the primary React2Shell CVE. Security researchers quickly highlighted the potential for complete server compromise through simple HTTP requests, stressing the gravity of an attack that requires no authentication.

Reports indicate that React servers using React Server Function endpoints and Next.js applications with default configurations are directly exploitable. While no widespread attacks have been confirmed yet, OX Security’s verification of an active proof-of-concept confirms the vulnerability is no longer theoretical. Meanwhile, JFrog’s warnings about fake PoCs highlight the additional risk of inadvertently running malicious code during remediation tests.

Immediate mitigation involves upgrading to fixed package versions, including React 19.0.1, 19.1.2, and 19.2.1, and applying App Router adjustments for Next.js apps. The urgency is clear: developers and security teams must act quickly to prevent potential large-scale exploitation.

What Undercode Say: Deep Analysis

React2Shell exposes a fundamental weakness in the server-side architecture of modern JavaScript frameworks. By targeting the deserialization logic, attackers can bypass traditional security measures that rely on authentication and access control. This is especially concerning because React and Next.js power millions of websites and web applications, from small startups to enterprise-level platforms. The risk extends beyond isolated servers to supply chains and integrated systems that depend on these frameworks.

The simplicity of exploitation—a single HTTP request—makes it accessible even to attackers with moderate technical skill. This marks a departure from many previous high-profile vulnerabilities that required complex chains or insider knowledge. The parallels drawn to Log4Shell are apt, as both vulnerabilities allow unauthenticated remote code execution with potentially devastating effects.

Organizations relying on React and Next.js need a multi-layered response. Immediate patching is critical, but additional measures should include monitoring server endpoints for unusual activity, validating proof-of-concept exploits in isolated environments, and auditing dependencies that might inherit the vulnerability. The presence of fake PoCs online adds a social engineering dimension: teams must exercise extreme caution when sourcing remediation scripts or testing exploits.

From a risk management perspective, React2Shell could have long-term implications for the trustworthiness of widely used JavaScript frameworks. Enterprises may reconsider reliance on server-side React and Next.js components until rigorous security reviews and sandboxing techniques are standardized. Security vendors, like Tenable and JFrog, are likely to see increased demand for automated detection and mitigation tools targeting this class of deserialization vulnerabilities.

Additionally, the vulnerability highlights a growing trend: the attack surface of front-end frameworks is expanding as more logic is moved to server-side execution for performance and interactivity. Historically, front-end libraries were perceived as lower-risk, but React2Shell demonstrates that even ubiquitous UI tools can become critical vectors for remote attacks. This will likely push development teams toward stricter security hygiene, code reviews, and dependency checks in the coming months.

🔍 Fact Checker Results

✅ React2Shell is a real, critical vulnerability in React.js (CVE-2025-55182).
✅ Next.js is affected due to shared framework components; CVE-2025-66478 is a duplicate.
❌ No confirmed mass exploitation reported yet, but active PoCs exist.

📊 Prediction

React2Shell is poised to dominate web security headlines for the foreseeable future. Expect rapid patch adoption across the React ecosystem, combined with temporary migration to safer configurations in Next.js applications. Exploitation attempts will likely rise, particularly targeting unpatched servers, making automated vulnerability scanning and real-time monitoring essential. Developers may accelerate adoption of server-side sandboxing and hardened deployment strategies. In the long term, this incident could catalyze stricter security standards for front-end frameworks and heightened awareness of deserialization threats. 🌐⚠️💻

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon