CVE-2025-55182: Critical Vulnerability, React2Shell, Allows for Unauthenticated RCE
December 5, 2025 · Cybereason · Severity: CRITICAL
A critical vulnerability, CVE-2025-55182 (dubbed React2Shell), was discovered in React on December 3, 2025, allowing unauthenticated remote code execution (RCE). Cybereason researchers warn the flaw is trivial to exploit, as servers incorrectly trust user-supplied identifiers without proper verification. A public proof-of-concept exploit has been linked to Chinese threat actors, increasing the risk of widespread attacks. Organizations using React versions exposed to the internet before the December 3 patch date should immediately investigate for signs of compromise. The vulnerability poses a severe threat due to its ease of exploitation and potential for unauthenticated RCE, enabling attackers to take full control of affected systems. Cybereason advises updating to the latest patched React versions and reviewing their advisory for additional mitigation steps. The public availability of an exploit increases urgency, as attackers may already be targeting unpatched systems. Proactive measures are critical to prevent large-scale breaches.
KEY TAKEAWAYS
- Critical vulnerability discovered on December 3, 2025 in React that could allow for unauthenticated remote code execution.
- Cybereason experts have dubbed this vulnerability as trivial to exploit.
- Issue allows the server to incorrectly trust user-supplied identifiers and fails to verify.
- Initial working proof of concept is public and attributed to Chinese threat actors.
- If server was exposed to public internet prior to patch release date (December 3, 2025), investigate for signs of compromise.
- Update to latest patched versions of React, and review advisory for additional recommendations.
Key Takeaways
- CVE-2025-55182: Critical Vulnerability, React2Shell, Allows — CRITICAL severity involving CVE-2025-55182
- Security advisory with actionable remediation guidance
- Apply vendor patches and monitor for exploitation activity