Post: This new React bug can drain your wallets if not caught

This new React bug can drain your wallets if not caught

164dd27cb965a09643d1a967934f67f040a161b0

a Critical weakness React server components are being actively exploited by multiple threat groups, putting thousands of websites – including crypto platforms – at immediate risk with users potentially seeing all of their assets wiped out if impacted.

The flaw was tracked and named as CVE-2025-55182 React2shellallows attackers to remotely execute code on affected servers without any authentication. React maintainers disclosed the issue on December 3 and assigned it the highest severity score.

Soon after the disclosure, GTIG witnessed widespread exploitation by economically motivated criminals and suspected state-backed hacking groups, targeting uncomplicated reactions and Next.js applications in cloud environments.