Unauthenticated attackers able to achieve remote-code execution

Synopsis

In December 2025, a critical vulnerability, CVE-2025-55182, dubbed React2Shell, affecting React Server Components, was rapidly exploited by various threat actors shortly after its public disclosure and patching by Meta and the React team. The vulnerab...

Companies

  • React

We've done the analysis so you can make the decisions

Search our repository of 8,300 high-quality, objective, peer-reviewed case studies, impacting 8,325 companies and resulting in $49,281,960,275 in net costs

  • Sophisticated search & querying
  • Financial data extracted
  • Key data points captured
Want to try before you buy? You can sample one of our case studies for free here