CISA Adds Critical React2Shell Vulnerability to KEV Catalog After Active Exploitation
The Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability affecting Meta's React Server Components to its Known Exploited Vulnerabilities (KEV) catalog.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability affecting Meta's React Server Components to its Known Exploited Vulnerabilities (KEV) catalog.
Identified as CVE-2025-55182 and named "React2Shell," this vulnerability is being actively exploited. It is a Remote Code Execution (RCE) vulnerability found within React Server Components, resulting from an issue in the framework's decoding of data payloads sent to React Server Function endpoints.
This flaw allows attackers to execute unauthorized commands due to improper data checking, enabling remote code execution without requiring authentication. Attackers can gain full control of the system, execute arbitrary code, or access sensitive data by sending specially crafted requests to vulnerable servers.
CISA's inclusion of CVE-2025-55182 in the KEV catalog indicates active exploitation by threat actors. Under Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies must secure their networks against this vulnerability by December 26, 2025.
Identified as CVE-2025-55182 and named "React2Shell," this vulnerability is being actively exploited.
Although this directive primarily applies to federal agencies, CISA advises all organizations, including private companies and state governments, to address this issue urgently. The time between vulnerability discovery and widespread attacks is decreasing, and active exploitation suggests that automated attack tools may already be targeting vulnerable servers.
Administrators should verify if their environments utilize vulnerable versions of React Server Components and apply mitigations as per vendor instructions. If a patch or mitigation is not available, CISA recommends discontinuing use of the affected product until it is secure.
For further information, visit the CISA KEV catalog .
Based on reporting by GBHackers.
