React2Shell: Tracking CVE-2025-55182 in React Server Components
React2Shell (CVE-2025-55182) is a remote-code-execution risk in React Server Components that also affects Next.js App Router deployments built with vulnerable React versions. Here’s what was reported, who is exposed, and how to remediate and harden going forward.