React2Shell
Application RCE → Kubernetes Workload → Cloud Credentials
Executive Summary
On December 3, 2025, the React team disclosed CVE-2025-55182, commonly called React2Shell, a critical remote-code-execution vulnerability affecting React Server Components. The vulnerability received a CVSS score of 10.0.
Cloudflare observed scanning and active exploitation within hours of disclosure. The vulnerability was particularly significant for Kubernetes environments because many affected applications (like Next.js apps) were deployed as internet-facing workloads running inside containers.
The Cloud Pivot
Wiz and Unit 42 subsequently reported exploitation against internet-facing Next.js applications resulting in compromised Kubernetes containers. Attackers were observed obtaining shells, harvesting credentials from environment variables and filesystems, querying cloud metadata, and successfully pivoting into the broader cloud infrastructure.
Vulnerability Mechanics
React2Shell resulted from an unsafe deserialization flaw in the React Server Components Flight protocol. Exploitation required a specially crafted HTTP request, without authentication, user interaction, or elevated privileges. Successful exploitation allowed arbitrary JavaScript execution on the affected server.
Kubernetes Attack Chain
The significance dramatically changes once the vulnerable application is running inside a Kubernetes cluster.
Unit 42 specifically documented attackers extracting mounted service-account tokens, querying the Kubernetes API, and collecting cloud credentials exposed through environment variables and metadata services.
Exploitation Speed
The incident is also important because of how quickly exploitation followed disclosure. Cloudflare observed scanning and active exploitation within hours. Wiz reported compromised victims beginning merely two days later on December 5, 2025.
This demonstrates a recurring, unavoidable property of modern internet-facing vulnerabilities:
Once the initial vulnerability discovery is automated by threat actors, the runtime becomes the next battlefield.
Analyst Assessment
React2Shell demonstrates why vulnerability management alone does not completely address cloud-native attack chains. Patching the application closes the initial vulnerability door, but it completely fails to answer the operational question: "What happened after exploitation?"
Once an attacker has execution inside a container, the security problem fundamentally changes. The relevant questions become strictly behavioral:
- What processes were created?
- What files were accessed?
- What credentials were read?
- What endpoints were contacted?
- What Kubernetes APIs were accessed?
- What identities were assumed?
Opsonance Point of View
React2Shell is a perfect demonstration of Opsonance's intended runtime-security boundary. The application layer can absolutely be compromised without the Kubernetes control plane itself ever being directly attacked.
The objective is to detect the post-exploitation transition rather than treating the application's RCE as the end of the incident.
An application process that suddenly: executes shell + reads credentials + accesses metadata + contacts external C2 has materially changed its runtime behavior. That behavioral transition is exactly where runtime security proves its value.
Key Finding
CONCLUSION
React2Shell demonstrates the sheer speed at which a framework application vulnerability can metastasize into a Kubernetes and cloud infrastructure compromise. The critical security boundary is not the application alone. It is the entire path from Application → Container → Identity → Kubernetes → Cloud.