• News/
  • https://www.bleepingcomputer.com/news/security/react2shell-critical-flaw-actively-exploited-in-china-linked-attacks/

Critical React2Shell flaw actively exploited in China-linked attacks

BleepingComputer
·
Bill Toulas
·
Published Dec 5, 2025
·
Updated

Multiple China-linked threat actors began exploiting the React2Shell vulnerability (CVE-2025-55182) affecting React and Next.js just hours after the max-severity issue was disclosed. React2Shell is an insecure deserialization vulnerability in the React Server Components (RSC) 'Flight' protocol. Exploiting it does not require authentication and allows remote execution of JavaScript code in the server's context. For the Next.js framework, there is the identifier CVE-2025-66478, but the tracking number was rejected in the National Vulnerability Database's CVE list as a duplicate of CVE-2025-55182. The security issue is easy to leverage, and several proof-of-concept (PoC) exploits have already been published, increasing the risk of related threat activity. The vulnerability spans several versions of the widely used library, potentially exposing thousands of dependent projects. Wiz researchers say that 39% of the cloud environments they can observe are susceptible to React2Shell attacks. React and Next.js have released security updates, but the issue is trivially exploitable without authentication and in the default configuration. A report from Amazon Web Services (AWS) warns that the Earth Lamia and Jackpot Panda threat actors linked to China started to exploit React2Shell almost immediately after the public disclosure. "Within hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, Amazon threat intelligence teams observed active exploitation attempt...

Read full article

Affected Software

2 affected components
Meta React
Vercel Next.js
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a critical React2Shell vulnerability affecting React and Next.js software.

2

What security implications are discussed in the article?

The article highlights that the React2Shell vulnerability is being actively exploited by China-linked threat actors shortly after its disclosure.

3

What specific vulnerability does the article focus on?

The article focuses on the insecure deserialization vulnerability identified as CVE-2025-55182 in the React Server Components 'Flight' protocol.

4

Which software products are affected by the React2Shell vulnerability?

The affected software products include Meta React and Vercel Next.js.

5

What type of threat actors are exploiting the React2Shell flaw?

The flaw is being exploited by multiple threat actors linked to China.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203