
- React2Shell (CVE‑2025‑55182) exploited to compromise hundreds of systems worldwide
- China‑linked groups and North Korea abuse flaw for persistence, espionage, and cryptomining
- Patch immediately to React versions 19.0.1, 19.1.2, or 19.2.1.
React2Shell, a critical severity vulnerability in React Server Components (RCS), was already used to compromise “several hundred machines across a diverse set of organizations”.