
A curated list of resources regarding CVE-2025-55182, the critical Remote Code Execution (RCE) vulnerability in React Server Components known as "React2Shell".
A curated list of resources regarding CVE-2025-55182, the critical Remote Code Execution (RCE) vulnerability in React Server Components known as "React2Shell".
Objective: To document the history, mechanics, and remediation of the React2Shell vulnerability for researchers and security engineers.
Official documentation and severity scoring.
react-server-dom-webpack, parcel, and turbopack.Technical deep dives into the root cause, exploitation chains, and the "Flight" protocol.
Rules, scripts, and WAF configurations to protect infrastructure.
cve-canary WAF rules.Real-time analysis, threads, and commentary from the security community.
Proof of Concepts (PoC).
Active threat actor reporting and wider industry coverage.
This library is community-maintained. Please read CONTRIBUTING.md to add a resource.