Emerging Threat: CVE-2025-55182 (React2Shell) - React Server Components RCE Vulnerability
On December 3 2025, the React team released patched versions of the affected React Server Components packages. Framework vendors, including Next.js, provided updated builds on the same day. Any environment using React Server Components or frameworks that embed the RSC pipeline should.