A serious vulnerability in the popular React and Next.js has raised concerns among security analysts, as it allows remote code execution without authentication. The issue, known as React2Shell (CVE-2025-55182), was discovered on December 3, 2025 , and became the target of attacks just hours after it was made public.

What is React2Shell and How Does It Work?
React2Shell is a deserialization vulnerability in the “Flight” protocol of React Server Components (RSC). It allows attackers to execute arbitrary JavaScript code in the server environment, exposing applications and infrastructure to significant risks.
For Next.js, there was a separate identifier CVE-2025-66478, but it was ultimately dismissed as a duplicate of React2Shell on the CVE list, emphasizing that the vulnerability affects both frameworks.
The exploit is relatively simple and does not require prior credentials, which significantly increases the risk. Wiz analysts estimate that 39% of observable cloud environments are vulnerable, while thousands of projects depend on the React and Next.js libraries.
See also: Vulnerability in NVIDIA Triton allows attackers to cause DoS attack
First Attacks and Danger From State-Level Groups
According to a report by Amazon Web Services (AWS), Chinese threat groups, such as Earth Lamia and Jackpot Panda, began exploiting React2Shell almost immediately after the CVE was made public.
“Within hours of the disclosure, AWS recorded active exploitation attempts by multiple Chinese state-owned groups,” the report states.
AWS honeypots also detected activity from infrastructure based in China, but did not attribute it to a specific group, reinforcing the sense that the exploitation is widespread and coordinated .
Targets and Geographic Scope of Attacks

The Earth Lamia team focuses on web application vulnerabilities and typically targets:
- financial institutions
- logistics and retail companies
- universities
- government organizations
Their attacks are recorded mainly in Latin America, the Middle East and Southeast Asia.
See also: Cacti vulnerability allows remote code execution
Accordingly, Jackpot Panda focuses on East and Southeast Asia, focusing on gathering information on corruption and internal security.
Published PoC and Active Exploitation
Researcher Lachlan Davidson, who reported the vulnerability, warned of fake exploits online. However, confirmed PoCs have appeared on GitHub by Stephen Fewer (Rapid7) and Joe Desimone (Elastic Security).
The attacks recorded by AWS included:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- running Linux commands like
whoamiandid - create files
/tmp/pwned.txt - attempts to read
/etc/passwd/
Analysts note that attackers are not limited to automated scans, but are actively adapting their techniques to real targets.
See also: Hackers exploit command injection vulnerability in Array AG Gateways

Protective Measures and Preventive Security
React and Next.js have released security updates to address CVE-2025-55182. Organizations are urged to:
- Implement new versions immediately.
- Assess all cloud and server for vulnerabilities.
- Use tools like the React2Shell scanner released by Assetnote on GitHub to detect vulnerable systems.
- Strengthen network securityby restricting access to React and Next.js servers.
React2Shell is a stark reminder that even the most popular libraries can be the target of rapid and coordinated attacks, and that prompt patching and monitoring is critical to application security.
Source: www.bleepingcomputer.com
