React2Shell is a 10/10 nightmare for web devs
A maximum-severity remote code execution vulnerability, CVE-2025-55182, is hitting React.js and Next.js servers. Dubbed React2Shell, it’s being actively exploited following a public PoC release on December 5, 2026.