How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Critical CVE in React Server Components Actively Exploited

calendar_today December 9, 2025 person Aqua Security domain aqua-security

A newly disclosed vulnerability in React Server Components (RSC) dubbed as CVE-2025-55182, and also known as React2Shell, has introduced a severe remote code execution (RCE) vector impacting applications built with React 19 and frameworks that rely heavily on RSC, most notably Next.js. The flaw received a CVSS score of 10.0, reflecting its ease of exploitation, &mldr

open_in_new Read original post