Back to Browse

Bugcrowd Security Flash: CVE-2025-55182 (React2Shell) UPDATE

1.3K views
Dec 10, 2025
21:34

On December 3, 2025, the React Team disclosed a critical RCE vulnerability (CVE-2025-55182) affecting React Server Components in modern Next.js deployments. In this Bugcrowd Security Flash, Casey Ellis and Matt Held outline what we've learned about this vulnerability since last week. They dig into the hardware exploitation element of this and also look at the AI-assisted exploitation side. Is "VibeCrime" the reason why this is moving faster than Log4shell? Check out the video to hear our take.

Download

1 formats

Video Formats

360pmp451.2 MB

Right-click 'Download' and select 'Save Link As' if the file opens in a new tab.

Bugcrowd Security Flash: CVE-2025-55182 (React2Shell) UPDATE | NatokHD