
"One crafted HTTP request can compromise your entire server." — React Security Team, Dec 2025
Severity: CRITICAL | CVSS v3.1: 10.0 (Maximum) | Status: Actively Exploited
React2Shell is a critical security vulnerability in React Server Components (RSC) — a modern feature that lets React run parts of your web app on the server instead of the browser.
The flaw allows any attacker on the internet — with no login, no special access, and no prior knowledge of your system — to send a single malicious HTTP request to your server and run any code they want on it. That means they can steal data, install malware, lock your files with ransomware, or take full control of your server.
Think of it like this: your server has a door that was supposed to only open for trusted visitors, but it turns out anyone can walk in — just by knocking in a specific way.
| Property | Value |
|---|---|
| CVE ID | CVE-2025-55182 (also called React2Shell) |
| Severity | Critical — Remote Code Execution (RCE) |
| CVSS v3.1 Score | 10.0 / 10.0 (maximum possible) |
| CVSS v4 Score | 9.3 / 10.0 |
| Weakness Type | CWE-502 — Deserialization of Untrusted Data |
| Attack Method | Single HTTP POST request, no authentication needed |
| Discovered By | Lachlan Davidson (security researcher) |
| Disclosed | December 3, 2025 |
| Exploit Status | Public exploit available — actively used by attackers |
| Related CVE | CVE-2025-66478 (Next.js — confirmed duplicate) |
react-server-dom-webpack — versions 19.0.0, 19.1.0, 19.1.1, 19.2.0
react-server-dom-parcel — versions 19.0.0, 19.1.0, 19.1.1, 19.2.0
react-server-dom-turbopack — versions 19.0.0, 19.1.0, 19.1.1, 19.2.0
| Framework / Tool | Affected Scope |
|---|---|
| Next.js 15.x – 16.x | App Router only — Pages Router is NOT affected |
| React Router RSC | Unstable / preview channel only |
| Redwood SDK | RSC mode only |
| Waku | All versions with RSC enabled |
| Expo | RSC preview builds only |
| Vite RSC Plugin | All integrations |
| Parcel RSC Plugin | All integrations |
| Any custom RSC setup | Any server using RSC Flight deserialization |
⚠️ Important: You are vulnerable even if you do not use Server Actions or Server Functions explicitly — as long as React Server Components are enabled in your app.
✅ Not affected: Apps using only the Pages Router, or apps with no server-side React at all.
Three reasons make React2Shell exceptionally severe:
No authentication required. Anyone on the internet can attempt this attack. No account, no token, no prior access needed.
Works on default installations. A brand-new Next.js app created with create-next-app — with zero custom configuration — is immediately exploitable. Developers do not have to do anything wrong to be vulnerable.
Near-100% reliability. Security researchers confirmed the exploit works almost every time against unpatched servers.
When your React server receives data from a client, it processes (deserializes) that data to understand what to do next. The problem is that React never checks whether that data is safe or legitimate — it blindly trusts whatever arrives.
An attacker exploits this by sending specially crafted data that hijacks internal JavaScript behavior on the server, ultimately allowing them to inject and execute their own code.
The exploit uses a technique called prototype pollution:
Object.prototype.then — a fundamental JavaScript object that all other objects inherit from.Function constructor.Function constructor to execute arbitrary code as the Node.js server process.Step 1 — Attacker sends crafted HTTP POST
↓
Step 2 — React deserializes payload blindly
↓
Step 3 — Object.prototype.then is hijacked (prototype pollution)
↓
Step 4 — Function constructor is accessed
↓
Step 5 — Attacker's code runs on the server
↓
Step 6 — Attacker has full server control
// This is a simplified version of the vulnerable code path inside React
function parseFlightRequest(req) {
const flight = req.body;
// ❌ NO validation — the server trusts whatever arrives
const decoded = dangerousDeserialize(flight); // Attack happens here
// If the attacker controls decoded.action → RCE
return executeServerReference(decoded.action);
}
POST /?flight=1 HTTP/1.1
Content-Type: text/plain
{
"status": "resolved_model",
"$1:__proto__:then": "node:process.mainModule.require('child_process').execSync('id > /tmp/rce')",
"_formData.get": "$1:constructor:constructor"
}
# Simplified cURL version of the exploit
curl -X POST https://target.com/react?flight=1 \
-H "Content-Type: text/plain" \
--data '["$ACTION_REF","__proto__","constructor","<attacker_payload>"]'
🚫 Legal warning: Do not use this against any system you do not own or have explicit written authorization to test.
| Package | Patched Version |
|---|---|
react-server-dom-webpack | 19.0.1, 19.1.2, 19.2.1+ |
react-server-dom-parcel | 19.0.1, 19.1.2, 19.2.1+ |
react-server-dom-turbopack | 19.0.1, 19.1.2, 19.2.1+ |
💡 Recommendation: Upgrade to 19.2.3 to also fix related follow-on vulnerabilities (CVE-2025-55183, CVE-2025-55184, CVE-2025-67779).
| Your Version | Upgrade To |
|---|---|
| 13.x / 14.x | 14.2.35 |
| 15.0.x | 15.0.5 |
| 15.1.x | 15.1.9 |
| 15.2.x | 15.2.6 |
| 15.3.x | 15.3.6 |
| 15.4.x | 15.4.8 |
| 15.5.x | 15.5.7 |
| 16.0.x | 16.0.7 |
Follow these steps in order. Step 1 and 2 are mandatory. The rest add extra layers of defense.
# Check your current version
npm list react-server-dom-webpack
# Upgrade to the latest patched version
npm install react-server-dom-webpack@latest
npm install react-server-dom-parcel@latest
npm install react-server-dom-turbopack@latest
# For Next.js — replace X with your patched version from the table above
npm install next@X