Multiple threat actors linked to China are actively exploiting the React2Shell vulnerability (CVE-2025-55182) shortly after its disclosure, leading to widespread attacks on React and Next.js applications. These attacks are facilitated by publicly available proof-of-concept exploits and are targeting various sectors globally, with several threat groups specifically focused on different regions; security updates have been issued but the vulnerability remains easy to exploit. #React2Shell #ChinaThreatActors
Keypoints
- The React2Shell vulnerability affects the React Server Components (RSC) βFlightβ protocol and allows remote JavaScript code execution without authentication.
- Multiple China-linked threat actors, including Earth Lamia and Jackpot Panda, began exploiting this vulnerability immediately after its public disclosure.
- The attack surface is significant, with an estimated 39% of observed cloud environments vulnerable to React2Shell exploits.
- Proof-of-concept exploits are available online, and real-world attacks are actively refining their techniques against targets.
- Security updates from React and Next.js have been issued, but many systems remain at risk due to easy exploitation in default configurations.