CVE-2025-66478 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
16
occurrences
First Seen
December 3, 2025
Last Seen
February 27, 2026

CVE-2025-66478 is a vulnerability tracked across 6 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed December 3, 2025; most recent activity February 27, 2026.

Related Threat Clusters

  • Critical CVSS 10.0 Vulnerability in React & Next.js Requires Immediate Patch

    A critical vulnerability with a CVSS score of 10.0 has been identified in React Server Components, specifically affecting the Flight protocol. This flaw allows unauthenticated attackers to execute remote code, impacting…

    3 articles · Updated February 27, 2026
  • Critical React Flaw CVE-2025-55182 Exposes Major Security Risks

    A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…

    47 articles · Updated December 3, 2025
  • Burp Suite Enhances Scanner for React2Shell Vulnerabilities

    Burp Suite has upgraded its scanning capabilities to detect critical React2Shell vulnerabilities in JavaScript applications. Both editions of Burp Suite now include the latest detection logic, allowing users to validate…

    4 articles · Updated December 9, 2025
  • Operation PCPcat Compromises Over 59,000 Next.js/React Servers

    Operation PCPcat has compromised 59,128 Next.js and React servers in under 48 hours, exploiting critical vulnerabilities CVE-2025-29927 and CVE-2025-66478. The attackers utilized prototype pollution in JSON payloads to…

    3 articles · Updated December 24, 2025
  • PCPcat Malware Compromises Over 59,000 Servers via React2Shell Exploit

    The PCPcat malware campaign has compromised more than 59,000 servers in under 48 hours by exploiting critical vulnerabilities in .js and React frameworks. It specifically targets vulnerabilities CVE-2025-29927 and…

    2 articles · Updated December 15, 2025
  • 0G Foundation Breached via Vulnerability Exploit

    The 0G Foundation experienced a security breach on December 5, 2025, due to a critical vulnerability in .js (CVE-2025-66478). The attacker exploited the emergency withdrawal function of the 0G reward contract, resulting…

    2 articles · Updated December 13, 2025

Recent Intelligence Reports

  • React2Shell (CVSS 10.0): Patch React & Next.js NOW | Unauth RCE Explained — Youtube · February 27, 2026
  • Operation PCPcat Hacked 59,000+ Next.js/React Servers Within 48 Hours — Cybersecuritynews · December 24, 2025
  • New PCPcat Exploiting React2Shell Vulnerability to compromise 59,000+ Servers — Cybersecuritynews · December 15, 2025
  • 0G Foundation Targeted in Attack Exploiting Vulnerability — Binance · December 13, 2025
  • How to detect React2Shell with Burp Suite — Blog.Portswigger · December 5, 2025
  • CVE-2025-55182 vulnerability in React and Next.js — Kaspersky · December 4, 2025
  • Maximum severity React vulnerability threatens extensive compromise — Scworld · December 4, 2025
  • React2Shell: RCE Vulnerabilities Require Immediate Attention — Sonatype · December 4, 2025

CVSS v3.1 Breakdown