broadcast Dec 4, 2025 · Bugcrowd
Bugcrowd Security Flash: CVE-2025-55182 (React2Shell) UPDATE
Bugcrowd published a security briefing video on YouTube examining CVE-2025-55182, a critical remote code execution vulnerability in React Server Components affecting Next.js deployments disclosed on December 3, 2025. Casey Ellis provides analysis and context on the vulnerability's implications for modern application security.
Source description — as published
On December 3, 2025, the React Team disclosed a critical RCE vulnerability (CVE-2025-55182) affecting React Server Components in modern Next.js deployments. ...