Attackers have increased the level of their attacks by exploiting a recently disclosed maximum severity vulnerability in React Server Components (RSC), Next.js , and related frameworks, known as React2Shell. Financially motivated attackers found a way to use the flaw, dubbed React2Shell (CVE-2025-55182), to execute arbitrary code on vulnerable servers via a single malicious HTTP request.
See also: Google: 5 more Chinese hacking groups exploit React2Shell

This allows them to quickly and easily gain access to a corporate network and deploy ransomware, according to researchers from cybersecurity firm S-RM and the Microsoft Defender Security Research Team. Initially, attackers exploited the vulnerability to introduce backdoor malware and crypto miners.
This new method represents a step up, and experts say it exposes a fundamental security weakness in front-end development. “For a long time, we’ve considered front-end development a low-level, low-risk task,” said David Shipley of Beauceron Security. “This is to the front end of applications what Log4j was to the back end, a huge opportunity for attackers.”
React is widely used in enterprise environments, with Microsoft researchers identifying “tens of thousands of distinct devices across several thousand organizations” running React or React-based applications.
React2Shell is a pre-authentication remote code execution (RCE) vulnerability affecting React Server Components (RSC), the open-source Next.js framework, and other related frameworks. It is rated a 10 on the Common Vulnerability Scoring System (CVSS) because it is easy to exploit, compromises many exposed systems, and is particularly vulnerable to automated attacks because it does not require authentication to execute.
The vulnerability specifically affects the Flight protocol, a core feature in the React development library and Next.js. RSC includes packages, frameworks, and bundlers that allow React applications to run parts of their logic on the server instead of in the browser.
Flight allows the server and client to communicate. When the client requests data, the server receives and parses a payload, performs server-side logic, and returns a human-readable software package. With the React2Shell vulnerability, affected RSCs fail to validate incoming payloads, allowing malicious users to inject malicious elements that React recognizes as legitimate.
See also: New React RSC vulnerabilities allow DoS and source code exposure

Attackers can send HTTP requests to trick the server into executing compromised code, potentially giving them “highly privileged” access to unpatched systems, according to S-RM researchers. According to initial reports of React2Shell, government agencies began exploiting the vulnerability within hours of its public disclosure. While the initial impact was limited to installing persistent backdoors on networks and mining cryptocurrency, React2Shell is now being used as the initial entry point in a ransomware attack.
S-RM notes that it is likely being used by “less sophisticated attackers” targeting publicly exposed web servers.
Microsoft researchers warn of the dangers of this vulnerability: It can be exploited with a single HTTP request. The default settings are vulnerable, meaning no special configuration is required and attackers do not have to wait for user errors. The exploit does not require authentication because it occurs before authentication. Exploit proofs show almost 100% reliability.
The researchers noted that they did not observe any lateral movement to other systems or attempts to steal data. S-RM advises businesses using RSC to verify that they are fully up-to-date. However, React has warned that even the initial patch releases (versions 19.0.2, 19.1.3, and 19.2.2) are vulnerable.
In addition to updating, organizations should conduct forensic reviews to check for: Unusual outbound connections that could indicate a C2 was executed. Disabling antivirus and endpoint protection, or purging or tampering with logs. Unusual spikes in resource usage, which could indicate crypto miners. Windows event logs or endpoint detection and response (EDR) telemetry that indicates attackers executed files in memory from binaries related to Node or React.
See also: React2Shell exploit distributes crypto miners
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It's worrying how long it's taking for the tech community to wake up to this threat. It could ultimately be a side effect of cuts to security teams and budgets, and developer burnout.
