Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

The founders have just raised funding to revisit the same problem: affordable custom home design.

Marissa Mayer’s startup Dazzle raises $8 million led by Forerunner’s Kirsten Green

Amazon’s AI assistant Alexa+ now works with Angi, Expedia, Square, and Yelp

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » React2Shell critical flaw added to CISA KEV after active exploitation
Identity

React2Shell critical flaw added to CISA KEV after active exploitation

userBy userDecember 6, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

December 6, 2025Ravi LakshmananVulnerability/patch management

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday officially added a critical security flaw affecting React Server Components (RSC) to its Known Exploited Vulnerabilities (KEV) catalog following reports of it being exploited in the wild.

This vulnerability, CVE-2025-55182 (CVSS score: 10.0), is related to remote code execution by an unauthenticated attacker with no special configuration required. Also tracked as React2Shell.

“A remote code execution vulnerability exists in Meta React Server Components that could allow unauthenticated remote code execution by exploiting a flaw in the way React decodes payloads sent to React Server Function endpoints,” CISA said in the advisory.

This issue is caused by unsafe deserialization in the Flight protocol, a library that React uses to communicate between servers and clients. This could result in a scenario where an unauthenticated, remote attacker could execute arbitrary commands on the server by sending a specially crafted HTTP request.

cyber security

“The process of converting text into objects is widely considered to be one of the most dangerous software vulnerabilities,” said Martin Zugec, Director of Technical Solutions at Bitdefender. “The React2Shell vulnerability exists in the react-server package, specifically in the way it parses object references during deserialization.”

This vulnerability is addressed in versions 19.0.1, 19.1.2, and 19.2.1 of the following libraries:

react server-dom-webpack react server-dom-parcel react server-dom-turbopack

Some downstream frameworks that rely on React are also affected. This includes Next.js, React Router, Waku, Parcel, Vite, and RedwoodSDK.

The development comes after Amazon reported that within hours of the flaw’s disclosure, it had observed attack attempts from infrastructure associated with Chinese hacker groups such as Earth Lamia and Jackpot Panda. Coalition, Fastly, GreyNoise, VulnCheck, and Wiz also reported seeing exploits targeting this flaw, indicating opportunistic attacks by multiple attackers.

Image source: GreyNoise

Some of the attacks include deploying a cryptocurrency miner and running a “cheap math” PowerShell command to confirm a successful exploit, followed by a command that drops an in-memory downloader that can retrieve additional payloads from a remote server.

According to data shared by attack surface management platform Censys, there are approximately 2.15 million instances of internet-facing services that could be affected by this vulnerability. It consists of public web services using React Server Components and public instances of frameworks such as Next.js, Waku, React Router, and RedwoodSDK.

cyber security

In a statement shared with The Hacker News, Palo Alto Networks Unit 42 said it has confirmed that more than 30 organizations across a variety of sectors have been affected, and that the chain of activity is consistent with a Chinese hacking group tracked as UNC5174 (also known as CL-STA-1015). This attack features the introduction of SNOWLIGHT and VShell.

“We observed scanning for vulnerable RCEs, reconnaissance operations, attempted theft of AWS configuration and credential files, and installation of downloaders that retrieve payloads from the attacker’s command and control infrastructure,” said Justin Moore, senior manager of threat intelligence research at Palo Alto Networks Unit 42.

Security researcher Lachlan Davidson, who is credited with discovering and reporting the flaw, has since released multiple proof-of-concept (PoC) exploits, making it imperative for users to update their instances to the latest version as soon as possible. Another working PoC was published by a Taiwanese researcher who goes by the GitHub handle maple3142.

According to Binding Operating Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies must apply the necessary updates to secure their networks by December 26, 2025.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWhat would have happened if Antony and Cleopatra had killed Octavian?
Next Article 1,800-year-old ‘piggy bank’ filled with Roman coins unearthed in French village
user
  • Website

Related Posts

Two Chrome extensions discovered to be secretly stealing credentials from over 170 sites

December 23, 2025

Interpol arrests 574 people in Africa. Ukrainian ransomware company pleads guilty

December 23, 2025

Google Workspace password manager tutorial

December 23, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The founders have just raised funding to revisit the same problem: affordable custom home design.

Marissa Mayer’s startup Dazzle raises $8 million led by Forerunner’s Kirsten Green

Amazon’s AI assistant Alexa+ now works with Angi, Expedia, Square, and Yelp

Lemon Slice gets $10.5 million from YC and Matrix to build digital avatar technology

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.