PULSE NAME
React2Shell (CVE-2025-55182): Dissecting a Node.js RCE Against a Production Next.js App
WHITE PetrP.73 2025-12-20 Modified: 2026-01-19
13
IOCs
MEDIUM VOLUME
The investigation into the cyberattack targeting a production Next.js application identified the exploitation of a critical vulnerability, CVE-2025-55182 (React2Shell), which allows for remote code execution (RCE). An analysis of over 12,000 log entries demonstrated that attackers successfully executed commands on the server. The initial exploitation initiated through a malformed HTTP POST request containing a malicious React Server Component (RSC) Flight payload, abusing a deserialization flaw. This vulnerability, disclosed in December 2025 and rated CVSS 10.0, quickly garnered attention due to widespread active exploitation.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Flight RSC Flight Nuts Anivia Cobalt Strike React2Shell Persistence Mirai
Indicators of Compromise (1 / 13 total)
All CIDR CVE URL domain email
TYPEINDICATORDESCRIPTIONCREATED
email luis.etr@avangenio.com 2025-12-20