CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation


Trend Micro researchers have previously published a blog on what organizations need to know about the actively exploited CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks.

RSC is a modern architecture where UI components run on the server instead of the browser, reducing JavaScript sent to clients. RSC communicate between client and server using a serialization protocol called “React Flight.” This protocol enables streaming of complex data structures that mirror the React component tree, allowing UIs to render progressively while awaiting backend responses. The sum of which can be called the RSC payload. Think of it as an RPC-over-HTTP mechanism where clients send “chunks” of serialized data to Server Functions.

Read more…
Source: Trend Micro


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • The CEVA Logistics data breach is having major knock-on effects across Europe – here’s what we know

    August 11, 2026

    CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves. CEVA has ...

  • UK MoD says no data leaked to China via drone vulnerability

    August 10, 2026

    Britain’s Ministry of Defence said on Monday that there is no evidence that military data was compromised after a cyber vulnerability was discovered in Royal Navy drones. The issue was identified during routine cybersecurity testing, the ministry said, adding that it continues to conduct security checks across its equipment and systems. Read more… Source:  EUROACTIV Sign up for the ...

  • Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

    August 7, 2026

    Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks and quickly found that thousands of public agencies and websites were at risk of being hacked. At the Def Con cybersecurity conference in Las Vegas on Friday, security researchers Robert Kruczek and Kamil Szczurowski said they wanted to understand ...

  • Buggy microcontrollers making up some of the world’s most important servers can be easily backdoored

    August 6, 2026

    Security researchers have discovered more than a dozen new vulnerabilities in Baseboard management controllers (BMC), hardware components found in thousands of the world’s most popular enterprise servers. BMCs are specialized chips built into servers that allow administrators to remotely monitor and manage hardware regardless of the operating system, and even when the hardware is turned off. They provide ...

  • Apple’s Private Relay tool can leak users’ IP addresses

    August 6, 2026

    WebKit, Apple’s engine that powers all web browsers in its ecosystem, contained multiple flaws that helped leak the IP addresses of users who paid to keep them hidden. This is according to security researchers Talal Haj Bakry and Tommy Mysk who noted they had found “three WebKit features that bypass the proxy configuration and send traffic directly from the ...

  • Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

    August 6, 2026

    It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API keys used by legitimate developers for access to popular AI platforms. These keys are known ...