December 9, 2025
By Aileen Ward
React2Shell: Critical RCE in React Server Functions Enables Full Remote Code Execution
A severe React2Shell RCE flaw in React Server Functions lets attackers execute code via crafted HTTP requests. This vulnerability is patched in React 19.2.1.