ThreatCluster

Microsoft Addresses React2Shell RCE Vulnerability in React Server Components

First seen 16 Dec 2025, 20:58 UTC GbhackersCybersecuritynews 45

Article Content

Browse articles
ThreatCluster

Microsoft has detailed mitigations for the React2Shell vulnerability (CVE-2025-55182), which allows remote code execution in React Server Components and .js environments. This critical flaw, with a CVSS score of 10.0, enables attackers to compromise servers via a single malicious HTTP request. Exploitation attempts were first detected in December 2025.