Find out if you are vulnerable to the React2Shell vulnerability
Find out if you are vulnerable to the React2Shell vulnerability, covering both official tracking IDs:
• React Server Component exposure – CVE-2025-55182
• Next.js App Router RCE chain – CVE-2025-66478
The SecPoint Penetrator verifies real-world exploitability using remote execution indicators for the Next.js RCE chain and correlates this with React Server Component exposure, helping organizations identify whether they are truly exposed, not just theoretically vulnerable.
If you are running modern Next.js App Router deployments, this is a critical check to include in your security assessments.
#secpoint #secpointpenetrator #nextrce #react2shell #cve #cybersecurity #vulnerabilityscanning #nextjs #react
