216.73.216.226

Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat Actors

· Published 08/12/2025 17:25 · Modified 21/12/2025 18:49

Export JSON

Essential information

Published
08/12/2025 17:25
Modified
21/12/2025 18:49
Tags
2025-12-08 CVE-2025-55182 active exploitation arbitrary code execution chinese threat actors gobrat react server components react2shell
Related entities
1 vulnerabilities (cve), 2 observables, 1 intrusion sets (apt), 6 techniques (mitre), 1 malware, 2 others

Description

A critical vulnerability dubbed '' () in is being actively exploited by . The flaw affects multiple versions and packages, allowing through crafted HTTP requests. Approximately 39% of scanned cloud environments contain vulnerable React instances, with exploitation attempts showing a near 100% success rate. The vulnerability impacts popular frameworks and libraries bundling react-server. Chinese state-sponsored groups, including Earth Lamia and Jackpot Panda, are reportedly involved in the attacks. Organizations are urged to identify vulnerable assets, apply patches immediately, and block malicious IP addresses associated with exploitation attempts.

External references