
Proof-of-concept exploit for CVE-2025-55182, an unsafe deserialization vulnerability in React Server Components enabling unauthenticated remote code execution via crafted payloads.
CVE-2025-55182 (also known as React2Shell) is a critical unsafe deserialization vulnerability discovered in the React Flight Protocol, affecting the payload of React Server Components (RSC). This vulnerability resides in the react-server package.
react-server packagereact-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack