# React2Shell Uncovered: What the Critical RCE Means - And What You Must Do

[Watch Now](/content/resources/webinars/react2shell-what-you-must-do#onDemand/index.html)

In December 2025, the security community uncovered a devastating flaw in React Server Components - React2Shell. This vulnerability (CVE-2025-55182 / CVE-2025-66478) enables unauthenticated remote code execution (RCE) through a single crafted HTTP request, potentially compromising servers - even for apps that don’t explicitly expose server functions. With React and Next.js powering millions of web applications globally - including many enterprise and consumer-facing platforms - the exposure is massive.

## What You’ll Learn:
- Exactly how React2Shell works: the root cause, the vulnerable React/Next.js versions, and how the exploit is triggered.
- How to audit your own applications: dependencies, frameworks and transitive usage that may expose you.
- Quick remediation steps: which versions to upgrade to, and how to apply patches with minimal disruption.
- Interim defensive controls: e.g. WAFs, runtime monitoring, dependency blocking — if you cannot patch immediately.
- Long-term strategies for supply-chain safety, dependency hygiene, and proactive vulnerability management.

## Featured Speakers
### Brian Fox  
CTO, Sonatype

### Tyler Warden  
SVP of Product, Sonatype
