Security Alert: CVE-2025-55182 (“React2Shell”)

 Gabriel Rodríguez
Gabriel Rodríguez
December 26, 2025
React
Security Alert: CVE-2025-55182 (“React2Shell”)

How VAIRIX is responding to a critical React Server Components vulnerability

On December 3, 2025, a critical security vulnerability (CVE-2025-55182) was disclosed in React Server Components, with a CVSS score of 10.0/10.0, being the highest possible. The issue, known as “React2Shell,” impacts React 19 and frameworks such as Next.js, and can allow attackers to run malicious code on servers without authentication.

With reports of exploitation starting just hours after disclosure, treating this as urgent is the safest move.

Scope and affected versions

If your application relies on React Server Components, review your setup right away. The affected stack includes:

  • React versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0
  • Next.js versions 15.x and 16.x using the App Router
  • Other frameworks that use React Server Components, including React Router, Waku, Vite RSC, and Parcel

How VAIRIX is handling it

We’re already working through this vulnerability across our client projects. React, React Native, and Next.js are at the center of what we build, and after 15 years working with this stack, security reviews and fast patching are part of our normal process.

Right now, our priority is simple: find any systems that could be exposed and apply the fixes needed to keep them protected.

Actions underway

Here’s how we’re handling the response across our projects:

  • Full review: Auditing all projects to identify vulnerable versions.
  • Patching: Rolling out security updates across affected applications.
  • Proactive communication: Contacting clients whose projects need immediate attention
  • Continuous monitoring: Tracking updates and guidance from the React and Next.js security teams.

This is the same approach we use for any security issue, tracking advisories closely, keeping dependencies up to date, following secure development practices throughout delivery, and testing carefully around every change.

Get a quick exposure check

If you’re running React 19 or Next.js 15/16 and you’re not fully sure where your application stands, we can help you get clarity quickly. Our team can do a fast assessment, confirm whether you’re exposed, and apply the right fixes with minimal disruption. 

With 15 years of experience working on React and Next.js projects for U.S. teams, we’re used to moving fast on security fixes while keeping the rollout controlled. 

This vulnerability is being actively exploited, so if you’re potentially exposed, it’s worth addressing it right away.

👉Need clarity today? Contact us here.

Official references

For more details, consult the official sources:

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

What to Watch? Showcase for the Bun, Astro, React & Nano Stores Stack‍

Discover the winning tech stack of Bun, Astro, React, and Nano Stores in web development. Uncover their unique synergy and advantages, and learn how to harness their power for your next project. Get insights, practical knowledge, and inspiration in this detailed showcase.

React
Web Development
Frameworks
Read more ->
May 27, 2024

Best Pre-Built Solutions & Libraries for React

Boost your React development with the best libraries and frameworks. From Next.js and Astro to Zustand and TanStack Query, discover essential tools for routing, state management, UI components, and performance optimization in modern web apps.

React
Read more ->
March 13, 2025

React testing Library

Learn how to leverage React Testing Library for unit testing to prevent production failure on your software development projects.

React
Redux
Jest
Read more ->
May 6, 2021

Get in Touch

Let's Discuss Your IT Augmentation Needs

Have questions or are interested in our IT Staff Augmentation services? We'd love to hear from you. Reach out to our team using the contact information below, and we'll be in touch shortly to discuss how we can support your projects.

Find Us!

One Beacon St, 15th Floor, Boston, MA 02108

What do you need help with?
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
"They're very collaborative, and they offer great benefits to us. The interaction is very important to us, and they take time to explain their process. They excel in all aspects of what we do, and I would recommend them to anybody."
Jonathan Wride
CEO at