CVE-2025-55182
- CVSS
- —
- EPSS
- 0.998 (100.0th percentile)
- CISA KEV
- Added 2025-12-05, due 2025-12-12
- Exploitation
- No report
- Public exploits
- 458 repositories
- State
- Unknown
Coverage
Actively exploitedCritical 95Huntress
PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182
Huntress is seeing threat actors exploit React2Shell (CVE-2025-55182) to deploy a Linux backdoor, a reverse proxy tunnel, and a Go-based post-exploitation implant.

Actively exploitedCritical 95Wiz Research
React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182
We break down the exploit mechanics and detail active in-the-wild attacks observed by our team, from credential harvesting to sophisticated cloud backdoors.
Actively exploitedCritical 95Vercel (blog + changelog)
React2Shell Security Bulletin
CVE-2025-55182 is a critical vulnerability in React that requires immediate action. Next.js and other frameworks that React are affected. Read the bulletin and act now. Read more

Actively exploitedCritical 95Wiz Research
React2Shell (CVE-2025-55182): Everything You Need to Know About the Critical React Vulnerability
Detect and mitigate React2Shell (CVE-2025-55182), critical RCE vulnerability in React and Next.js exploited in the wild. Organizations should patch urgently.
Actively exploitedCritical 95Vercel (blog + changelog)
Summary of CVE-2025-55182
See the for the latest updates. React2Shell security bulletin Summary Impact Resolution Credit References CVE-2025-55182 CVE-2025-66478 A critical-severity vulnerability in React Server Components () affects React 19 and frameworks that use it, including Next.js (). Under certain conditions…
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev