Search results for "REACT"
2026-03-03
05:50

React critical vulnerability exploited on a large scale, crypto platform faces token theft risk

Recently, a high-severity security vulnerability disclosed in React server components has raised significant industry concern. The vulnerability, numbered CVE-2025-55182 and also known as React2Shell, has been actively exploited by multiple threat groups, affecting thousands of websites including cryptocurrency platforms, putting user assets at direct risk. This vulnerability allows attackers to execute remote code on affected servers without authentication. The React team publicly disclosed the issue on December 3rd, rating its severity at the highest level. Subsequently, Google Threat Intelligence Group (GTIG) confirmed that the vulnerability has been rapidly weaponized in real-world environments, involving both profit-motivated hackers and suspected state-sponsored attacks, targeting cloud-deployed, unpatched React and Next.js applications.
More
06:20

React vulnerability exploited by hackers, cryptocurrency websites face a wave of JavaScript theft attacks

Recently, a type of front-end attack targeting cryptocurrency users has been spreading rapidly. According to the cybersecurity non-profit organization Security Alliance (SEAL), hackers are exploiting a newly discovered vulnerability in the open-source front-end JavaScript library React to implant cryptocurrency theft programs into legitimate websites, with a significant increase in related attack cases. React is one of the most mainstream web front-end frameworks currently, widely used to build various websites and web applications. On December 3rd, React's official team disclosed that a serious security vulnerability, numbered CVE-2025-55182, was discovered by white-hat hacker Lachlan Davidson. This vulnerability allows unauthenticated remote code execution, enabling attackers to inject and execute malicious code on the website's front end.
More