CVE-2025-66478General

CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Rejected reason: This CVE is a duplicate of CVE-2025-55182.

8.0/ 10 priority

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 18 mentions across 15 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 9 signals
  • General: 8 classified signals
  • Peaked 11d ago at 2 mentions (2026-02-25); latest day: 1
  • 18 total mentions across 15 days

Deep dive

Activity timeline18 mentions / 15d
01122Mentions · 2026-01-28: 1Mentions · 2026-02-05: 1Mentions · 2026-02-19: 1Mentions · 2026-02-25: 2Mentions · 2026-02-26: 2Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-06: 1Mentions · 2026-03-22: 1Mentions · 2026-03-26: 1Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2Mentions · 2026-04-03: 1Mentions · 2026-05-12: 1Mentions · 2026-06-02: 1PoC Mentioned / Linked · 2026-03-22: 1PoC Mentioned / Linked · 2026-04-01: 1Exploit Tool / Code · 2026-03-22: 1Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-04-01: 2Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-05-12: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-04-01: 2Patch / Workaround · 2026-04-03: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 2Technical Details · 2026-03-22: 1Technical Details · 2026-04-01: 2Technical Details · 2026-04-03: 1Technical Details · 2026-05-12: 1Technical Details · 2026-06-02: 101-2802-0502-1902-2502-2603-0303-0403-0603-2203-2603-3104-0104-0305-1206-02
Signal classification5 categories
General
844.4%
Active Exploitation
527.8%
Patch
211.1%
Disclosure
211.1%
Exploit
15.6%
Referenced assets17 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-281
General1
2026-02-051
General1
2026-02-191
Patch1
2026-02-252
Disclosure1Patch1
2026-02-262
Active Exploitation1Disclosure1
2026-03-031
General1
2026-03-041
General1
2026-03-061
General1
2026-03-221
Exploit1
2026-03-261
General1
2026-03-311
General1
2026-04-012
Active Exploitation2
2026-04-031
Active Exploitation1
2026-05-121
Active Exploitation1
2026-06-021
General1
Full discourse18 posts
  • Intigriti@intigriti
    General

    @hakluke @xnl_h4ck3r @_jensec 6️⃣ React2shell-scanner React2shell-scanner by @assetnote is a Python CLI tool that detects CVE-2025-55182 & CVE-2025-66478 in Next.js apps, with WAF bypass support built in! 😎 🔗 https://github.com/assetnote/react2shell-scanner https://t.co/20y1ARF70u

    Post summary

    The tweet announces a Python CLI tool that scans Next.js applications for CVE‑2025‑55182 and CVE‑2025‑66478, offering built‑in WAF bypass, but provides no exploit, patch, or technical vulnerability details.

    12085859
    205.2K followersView on X
  • reverseame@reverseame
    General

    High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) https://slcyber.io/research-center/high-fidelity-detection-mechanism-for-rsc-next-js-rce-cve-2025-55182-cve-2025-66478/

    Post summary

    The text announces a detection mechanism for the RSC/Next.js remote code execution vulnerabilities CVE-2025-55182 and CVE-2025-66478, but it does not provide exploit details, patches, or evidence of active exploitation.

    03013809
    21.9K followersView on X
  • tmuxvim@tmuxvim
    General

    @dataTranslator https://nextjs.org/blog/CVE-2025-66478

    Post summary

    The tweet only links to a blog post about CVE-2025-66478 without providing further details.

    10130259
    12.4K followersView on X
  • sora@sorafujitani
    General

    @kobenisikakatan https://unit42.paloaltonetworks.com/ja/cve-2025-55182-react-and-cve-2025-66478-next/

    Post summary

    The tweet simply links to a Palo Alto Networks article about two CVEs, offering no direct information on exploitation, patches, or technical specifics.

    10021311
    1.0K followersView on X
  • Valentin Drăgănescu@escu__valentin
    General

    @_adembilican_ @coolifyio @Hetzner_Online All the kudos the the German Federal Office for Information Security for letting you know you are vulnerable and you should fix the issue :). I received such emails when NextJS was impacted by CVE-2025-66478 a few months ago :)

    Post summary

    The tweet references CVE‑2025‑66478 and a call to remediate the issue, but omits technical details, PoC, or evidence of exploitation.

    10030214
    173 followersView on X
  • Stefano Saitta@nerder_
    Disclosure

    @rauchg Your non-vibecoded framework Next also had 1 critical (CVE-2025-66478), 1 high (CVE-2025-55184), and 1 medium (CVE-2025-55183) security vulnerabilities.

    Post summary

    The tweet announces that the framework Next contains three vulnerabilities—one critical, one high, and one medium—without providing further technical details or mitigation steps.

    00040144
    164 followersView on X
  • Sachit@cyb3r_17
    Patch

    @FakeUncleNemo I think it's related to this: https://nextjs.org/blog/CVE-2025-66478 if you're using next.js pls update your site!

    Post summary

    The post references a CVE affecting Next.js and urges users to update their sites, indicating a patch is required.

    10030104
    766 followersView on X
  • ͏Freddie Quinson@QuinsonFreddie
    Active Exploitation

    Waiting gracefully for OKC belt tonight, my next js project decided it was the perfect time to try me. Runtime logs showed that it was passing a n attackers input int child_process.exec. Confirmed I was being hit by CVE-2025-66478. exec call only failed because I was using..

    Post summary

    The author confirms active exploitation of CVE-2025-66478 via child_process.exec, providing minimal technical detail and no patch information.

    10100847
    1.7K followersView on X
  • Rodrigo Moreno@RodMoreno_
    Active Exploitation

    Interesting timing to lecture about security. In the last 3 months alone, your stack shipped: • CVE-2025-66478 — RCE, CVSS 10.0. Exploited in the wild by nation-state actors. • CVE-2025-55184 — DoS, CVSS 7.5. Initial patch was incomplete, required a 2nd fix.

    Post summary

    The post highlights two recent CVEs, noting that CVE‑2025‑66478 (an RCE with CVSS 10.0) has been exploited in the wild by nation‑state actors, while CVE‑2025‑55184 (a DoS with CVSS 7.5) suffered an incomplete initial patch requiring a second fix.

    10010138
    317 followersView on X
  • Davin Jackson@Djax_Alpha
    Disclosure

    React2shell: CVE-2025-55182 Critical RCE Vulnerability in React and Next.js https://api.cyfluencer.com/s/react2shell-cve-2025-55182-cve-2025-66478-critical-rce-vulnerabilities-in-react-and-next-js-25541/1

    Post summary

    The text announces a critical RCE vulnerability (CVE-2025-55182) affecting React and Next.js, but provides no details on PoC, exploitation, or patches.

    00011154
    9.1K followersView on X
  • chester@mdsiaofficial
    General

    Securing the Modern Web - React and Next.js Applications [ React2Shell CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) ] https://medium.com/@mdsiaofficial/securing-the-modern-web-react-and-next-js-ff71015aa1c8

    Post summary

    The text references CVE-2025-55182 and CVE-2025-66478 with a Medium article link, but provides no further details on exploitation, mitigation, or technical specifics.

    00020126
    366 followersView on X
  • xymox@clxymox
    General

    📌 High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) 🔹 Détection automatique des CVE 🔹 Analyse des composants React 🔗 https://github.com/assetnote/react2shell-scanner #Python

    Post summary

    The post introduces a new detection scanner for Next.js RCE CVEs (CVE‑2025‑55182 & CVE‑2025‑66478) and provides a GitHub link for the tool.

    0000048
    456 followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    🚨 Threat Alert: Next.js Hosts Compromised via React2Shell (CVE-2025-55182) — Automated Credential Harvesting (UAT-10608) 📅 Date: 2026-04-03 📆 Timeline: 2025-12-03: CVE-2025-55182 disclosed. 2025-12-05 onward: in‑the‑wild exploitation. Dec 2025: multiple vendors publish telemetry. 2026-04-03: Cisco Talos reports UAT-10608 — 766 hosts observed in 24h. 📍 Location: Global (web applications worldwide) 📌 Attribution: Primary cluster: UAT-10608 (Cisco Talos). Other clusters observed by Google, Microsoft, AWS (UNC6600/6586/6588/6603/6595). Multiple opportunistic criminal and some nation‑nexus activity; no definitive public state attribution. 📝 Summary: Cisco Talos reports an automated credential‑theft campaign (UAT-10608) exploiting React2Shell (CVE-2025-55182) in React Server Components/Next.js. Attackers used unauthenticated RCE to deploy web shells and scripts that harvested DB credentials, SSH keys, cloud tokens, GitHub tokens and API keys from internet‑facing Next.js hosts. Hundreds of hosts were compromised rapidly after disclosure. ⚔️ Attack Details: - Attack Type: Credential theft via unauthenticated remote code execution (React2Shell) with post-exploit web shells, downloaders, and backdoors - Target: Internet-facing Next.js applications / React Server Components (over 700 compromised servers; Cisco Talos: 766 hosts recorded by NEXUS Listener) 📈 Impact: >700 servers compromised; widespread theft of database credentials, private SSH keys, cloud credentials (AWS/Azure/GCP), GitHub tokens and API keys; risk of account takeover, lateral movement, persistence, data exfiltration, and supply‑chain/code integrity abuse. Operational scale: 766 hosts observed in 24 hours by Cisco Talos. No public quantified financial loss reported. 🔗 Related Resources: - https://cybersecuritynews.com/700-next-js-hosts-exploited/ - https://blog.talosintelligence.com/uat-10608-inside-a-large-scale-automated-credential-harvesting-operation-targeting-web-applications/ - https://cloud.google.com/blog/topics/threat-intelligence/threat-actors-exploit-react2shell-cve-2025-55182 - https://nextjs.org/blog/CVE-2025-66478 - https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/ 🛡️ Recommended Actions: - Patch immediately: upgrade React / React Server Components and Next.js to vendor‑patched versions. - Rotate all secrets, API keys, and tokens after patching and redeploy. - Deploy WAF rules (Cloud Armor / Azure WAF / vendor rules) as temporary compensating control. - Restrict cloud metadata access (IMDS) and apply least privilege for instance roles. - Enable EDR and hunt for indicators: suspicious node/next-server child processes launching curl/wget, hidden dirs (e.g., $HOME/.systemd-utils), new cron/systemd services, modifications to authorized_keys. - Revoke and rebuild suspected‑exfiltrated credentials (SSH keys, cloud keys, GitHub tokens). - Isolate and perform incident response on compromised hosts; collect forensic artifacts and scan estate for vulnerable package versions. - Implement ongoing secrets scanning, credential hygiene, and vulnerability management. 🫨 Attack Vectors: - T1190 - Exploit Public-Facing Application (React2Shell / CVE-2025-55182) - T1059 - Command and Scripting Interpreter (bash, curl/wget execution to fetch payloads) - T1505.003 - Server Software Component: Web Shell (in-memory web shells / Next.js web shell deployments) - T1078 - Valid Accounts (use and abuse of stolen credentials/SSH keys) - T1555 - Credentials from Password Stores/Files (secret discovery tools and scripts: TruffleHog, Gitleaks, custom stealers) - T1086 - PowerShell (encoded/obfuscated commands observed in post-exploit activity) 🏷 Tags: #credential-theft #Next.js #React2Shell #CVE-2025-55182 #web-RCE #UAT-10608 #CiscoTalos #Cybersecurity

    Post summary

    The post reports that CVE‑2025‑55182 is actively exploited worldwide via an unauthenticated RCE in React Server Components/Next.js, with large‑scale credential theft, and recommends immediate patching and mitigation steps.

    00000196
    277 followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    🚨 Threat Alert: EtherRAT / EtherHiding Blockchain C2 Malware Campaign 📅 Date: 2026-04-01 📆 Timeline: 2025-12-05 to 2025-12-12: React2Shell (CVE-2025-55182) disclosed and early exploitation observed; 2025-12-08: Sysdig published detailed EtherRAT analysis; Dec 2025–Mar 2026: multiple vendor observations and telemetry (Unit42, eSentire); 2026-03: eSentire TRU reported a retail intrusion with EtherRAT and EtherHiding C2; 2026-04-01: GBHackers and others reported on ongoing activity. 📍 Location: Global (internet-exposed React/Next.js servers; observed across multiple industries) 📌 Attribution: Reported and analyzed by Sysdig and Unit42; operational overlaps with DPRK-associated "Contagious Interview" activity and UNC5342 reported by multiple vendors (medium confidence). NOT confirmed with 100% confidence. 📝 Summary: EtherRAT is a Node.js backdoor that uses an Ethereum-based technique called "EtherHiding" to store and rotate command-and-control (C2) endpoints in smart contract state, making takedown and detection difficult. It is multi-stage (downloader → Node.js runtime fetch → encrypted dropper → implant), supports arbitrary JavaScript execution via an AsyncFunction/eval-style construct, downloads its own Node runtime, and implements multiple persistence mechanisms (systemd user service, XDG autostart, cron, .bashrc/.profile). Public reporting (Sysdig, Unit42, eSentire) links EtherRAT operationally to React2Shell (CVE-2025-55182) exploitation and shows overlaps with DPRK-associated activity (Contagious Interview / UNC5342), though final attribution is not confirmed. ⚔️ Attack Details: - Attack Type: Backdoor / Blockchain-based Command-and-Control (C2) Malware - Target: Internet-facing servers and hosts running Node.js workloads and React/Next.js RSC endpoints (observed in retail, business services, software and finance environments); both Linux and Windows hosts where Node.js can run 📈 Impact: Persistent remote access and full remote code execution on compromised hosts; covert, resilient C2 (blockchain-resolved) resistant to classic takedowns; potential data theft, lateral movement and deployment of secondary payloads; remediation and incident response costs can be substantial (varies by victim — from tens of thousands to potentially $1M+ for large breaches). Exact data loss and monetary impact not publicly disclosed. 🔗 Related Resources: - https://www.sysdig.com/blog/etherrat-dprk-uses-novel-ethereum-implant-in-react2shell-attacks - https://gbhackers.com/ethereum-based-etherrat/ - https://unit42.paloaltonetworks.com/cve-2025-55182-react-and-cve-2025-66478-next/ - https://www.esentire.com/blog/etherrat-sys-info-module-c2-on-ethereum-etherhiding-target-selection-cdn-like-beacons - https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding 🛡️ Recommended Actions: - Patch React/Next.js and affected RSC components (apply vendor patches for CVE-2025-55182). - Isolate and forensically image suspected hosts; rebuild from known-good images where compromise is confirmed. - Rotate credentials and secrets accessible from compromised hosts. - Deploy EDR/NGAV with Node.js/JS runtime behavioral rules; enable runtime protection (e.g., Falco/Sysdig rules). - Monitor for outbound Ethereum RPC calls (eth_call) and unusual connections to public RPC endpoints; block unnecessary outbound access to public Ethereum RPC providers. - Hunt for randomized GET patterns (/api/{random}/{bot_id}/{random}.{ext}) and X-Bot-Server header; look for randomized $HOME/.local/share/ directories, random-named systemd user services, XDG autostart and cron @reboot entries, and unexpected nodejs downloads. - Apply egress filtering and WAF rules to detect/block React2Shell exploitation; block known staging IPs/URLs. - Remove persistence artifacts, update detection content and TI feeds, and engage IR/MDR if required. 🫨 Attack Vectors: - T1190 - Exploit Public-Facing Application: React2Shell (CVE-2025-55182) used as initial access in multiple reports. - T1105 - Ingress Tool Transfer: Download of Node.js runtime and staged payloads from attacker-controlled staging servers (e.g., http://193.24.123.68:3001). - T1059.007 - Command and Scripting Interpreter: JavaScript/Node.js: Execution of arbitrary JavaScript via AsyncFunction/eval-like constructs; operators can run arbitrary Node.js modules. - T1071 - Application Layer Protocol (HTTPS): C2 polling over HTTPS, mimicking CDN asset requests (.png/.css/.ico) to blend in with normal traffic. - T1027 - Obfuscated Files or Information: Use of JavaScript obfuscator (http://Obfuscator.io) and re-obfuscation/rewrite behavior from C2. - T1547.001 - Boot or Autostart Initialization: Systemd/User Service: Persistence via randomly-named systemd user services, XDG autostart, cron @reboot entries, and shell config injection. - Custom - Blockchain-based C2 (EtherHiding): Use of Ethereum smart contract state and transactions to store/rotate C2 endpoints; consensus across multiple public RPC endpoints for resilience. 🏷 Tags: #malware #backdoor #EtherRAT #EtherHiding #Ethereum #blockchain #Node.js #C2 #UNC5342 #ContagiousInterview #DPRK #Cybersecurity

    Post summary

    The text reports that the EtherRAT/ EtherHiding malware campaign has been actively exploiting the React/Next.js CVE‑2025‑55182 in the wild, with multiple vendor confirmations and ongoing activity, and provides accompanying mitigation advice.

    00000210
    276 followersView on X
  • The Martinez@K0val3nt
    Active Exploitation

    Yesterday, the CBN issued an advisory, based on guidance from ngCERT, warning financial institutions about critical vulnerabilities (CVE-2025-55182 and CVE-2025-66478) in React Server Components (versions 19.0 to 19.2) and Next.js (versions 15 to 16) that could allow unauthenticated remote code execution due to insecure deserialization in the RSC “Flight” protocol. These flaws pose serious risks including full system compromise, data theft, ransomware attacks, and operational disruption, especially as active exploitation attempts and proof-of-concept tools already exist. Institutions are therefore required to urgently identify affected systems, apply patches or mitigations, enhance monitoring, conduct forensic assessments, notify relevant vendors, and promptly report any suspected or confirmed incidents to the CBN.

    Post summary

    The advisory highlights critical RSC/Next.js vulnerabilities that support unauthenticated remote code execution, notes that active exploitation and PoC tools exist, and urges immediate patching and monitoring.

    0000048
    3.2K followersView on X
  • John Christly@christly
    Exploit

    https://api.cyfluencer.com/s/react2shell-cve-2025-55182-cve-2025-66478-critical-rce-vulnerabilities-in-react-and-next-js-26109/1

    Post summary

    The piece discloses critical remote‑code‑execution vulnerabilities in React and Next.js, shares PoC/exploit code, and outlines available patches and mitigations.

    0000097
    436 followersView on X
  • Grok@grok
    Patch

    @DrClapsIty @Dz10Chiheb Hayır, Next.js 16.1.6'da CVE-2025-55182 (veya ilgili CVE-2025-66478) sorunu giderilmiş. Etkilenen sürümler 15.0.0 - 16.0.6 arası. Güncel sürüme yükseltmek önerilir.

    Post summary

    Next.js has patched CVE-2025-55182 (and the related CVE-2025-66478) in version 16.1.6; users of affected 15.0.0–16.0.6 should upgrade to mitigate the vulnerability.

    0000043
    8.0M followersView on X
  • Declan Middleton@declanmidd
    General

    A critical vulnerability has been identified in the React Server Components (RSC) protocol | NEXTJS 15, 16 CVE-2025-66478 #cybersecurity https://t.co/PfAyEW9fm4

    Post summary

    The tweet announces the discovery of a critical CVE-2025-66478 in Next.js's React Server Components protocol but provides no technical details, exploits, or remediation information.

    00000119
    2 followersView on X

Explore more