TGViewer
MahadSec MahadSec @mahadsec · 177 subscribers
Post #18 956
CVE-2025-55182 — React2Shell

🔴 CVSS 10.0. Unauthenticated RCE in React Server Components.

One crafted HTTP request to a Server Function endpoint → code execution on the server. No login. Default configs. Actively exploited in the wild.

If you’re running React 19 RSC / Next.js App Router and haven’t patched — do that first.

🗃 Affected packages: react-server-dom-webpack, -parcel, -turbopack (19.0 / 19.1.0–19.1.1 / 19.2.0).

Reading the advisory isn’t enough though.

Want to actually understand the attack path - enum the surface, craft the payload, get a shell, and see why this class of bug is
so dangerous?

Practice it on KickStore, an Easy Linux machine on MahadSec built around this vulnerability class.

🛡 https://my.mahadsec.com/standalone-labs/machine/kickstore

📁 Patch your apps. Then break the lab version so you recognize it next time it shows up in a real engagement.
  • 👍 2
More from @mahadsec
  1. Sep 22, 2026🛡 New CTF challenges released 🏁 Capture The Flags Now: https://my.mahadsec.com/ctf/chall…
  2. Sep 21, 2026Post #23
  3. Sep 19, 2026🛡 SmarterMail: Unauthenticated file upload (CVE-2025-52691) Practice with Ring: 🔗 https:…
  4. Sep 17, 2026🇺🇿 O'zbekistondagi startuplar uchun taklif. 👨‍💻Hamma loyihasini qurish, investor topis…
  5. Sep 16, 2026🏁 Mahadsec CTF is also live now! Is solving machines too challenging right now? Start wit…
  6. Sep 12, 2026🐞 CVE-2025-24813 — Apache Tomcat (CVSS 9.8) A path equivalence bug in Tomcat’s Default Se…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →