
React2Shell: Critical RCE in React & Next.js
CVE-2025-55182 is a critical RCE in React 19 and Next.js from unsafe deserialization in React Server Components. Exploitable by crafted HTTP requests in default configs. Patch urgently to avoid cloud credential theft and cryptojacking.









