Skip to content

A curated list of resources regarding CVE-2025-55182, the critical Remote Code Execution (RCE) vulnerability in React Server Components known as "React2Shell".

License

Notifications You must be signed in to change notification settings

websecuritylabs/React2Shell-Library

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 

Repository files navigation

React2Shell Library

Awesome CVE-2025-55182 Topic

A curated list of resources regarding CVE-2025-55182, the critical Remote Code Execution (RCE) vulnerability in React Server Components known as "React2Shell".

Objective: To document the history, mechanics, and remediation of the React2Shell vulnerability for researchers and security engineers.

📚 Library Contents


Core Intelligence

Official documentation and severity scoring.

Research & Analysis

Technical deep dives into the root cause, exploitation chains, and the "Flight" protocol.

Detection & Defense

Rules, scripts, and WAF configurations to protect infrastructure.

Community & Discussion

Real-time analysis, threads, and commentary from the security community.

  • @maple3142 (Dec 4, 2025) - Release of the first working Proof of Concept (PoC) for Next.js 16.0.6, confirming the vulnerability was exploitable.

Exploitation

Proof of Concepts (PoC).

Media & Threat Intel

Active threat actor reporting and wider industry coverage.


Contributing

This library is community-maintained. Please read CONTRIBUTING.md to add a resource.

About

A curated list of resources regarding CVE-2025-55182, the critical Remote Code Execution (RCE) vulnerability in React Server Components known as "React2Shell".

Resources

License

Contributing

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published