← Back to Feed

CVE-2025-55182: Critical Vulnerability, React2Shell, Allows for Unauthenticated RCE

CVE-2025-55182

December 5, 2025 · Cybereason · Severity: CRITICAL

This article announces CVE-2025-55182, a critical unauthenticated remote code execution vulnerability in React. Cybereason experts have found it trivial to exploit and have observed a public PoC attributed to Chinese threat actors. Organizations are urged to patch immediately and investigate for compromise.

Cybereason is continuing to investigate. Check the Cybereason blog for additional updates. 
 
 

KEY TAKEAWAYS

  • Critical vulnerability discovered on December 3, 2025 in React that could allow for unauthenticated remote code execution. 
  • Cybereason experts have dubbed this vulnerability as trivial to exploit. 
  • Issue allows the server to incorrectly trust user-supplied identifiers and fails to verify. 
  • Initial working proof of concept is public and attributed to Chinese threat actors. 
  • If server was exposed to public internet prior to patch release date (December 3, 2025), investigate for signs of compromise. 
  • Update to latest patched versions of React, and review advisory for additional recommendations.  

Key Takeaways

  • Critical vulnerability discovered December 3, 2025 in React allows unauthenticated remote code execution.
  • Cybereason experts have labeled this vulnerability as trivial to exploit.
  • Issue allows the server to incorrectly trust user-supplied identifiers and fails verification.
☕ Buy a Coffee