#ReactServer

Hans-Christoph Steinereighthave@librem.one
2025-12-10

Just to be sure, I scanned all apps on @fdroidorg and found no apps that used the libs vulnerable to #ReactServer #CVE-2025-55182 aka #React2Shell.

I'm no #Javascript nor #React dev though, maybe it was silly to scan apps for server components? In any case, #FDroid's data collection is easy to scan via scripts, so better safe than sorry.

2025-12-05

Maximum-severity #vulnerability threatens 6% of all #websites

#Security defenders are girding themselves in response to the disclosure of a maximum-severity vulnerability disclosed Wednesday in #ReactServer , an open source package that’s widely used by websites and in cloud environments. The vulnerability is easy to #exploit and allows #hackers to execute #malicious code on #servers that run it.
#react

arstechnica.com/security/2025/

PressMind Labspressmind
2025-12-05

Krytyczna luka w React Server – jedno żądanie do RCE w chmurze

Jedno żądanie HTTP i cudzy kod ląduje na twoim serwerze. Brzmi jak urban legend z konferencji security?

Czytaj dalej:
pressmind.org/krytyczna-luka-w

Ilustracja przedstawiająca serwer z zagrożeniem RCE w ciemnym otoczeniu.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst