React hack December 2025: How to respond to CVE‑2025‑55182 & follow‑up vulnerabilities

When the React team announced a critical vulnerability in React Server Components on December 3 2025, the JavaScript community collectively held its breath. The flaw – tracked as CVE‑2025‑55182 and informally dubbed React2Shell – allowed unauthenticated attackers to execute arbitrary code on servers running React’s new Server Function protocol. Worse, the default configuration of frameworks like Next.js meant […]