Two hacking groups with ties to China have been observed
weaponizing the newly disclosed security flaw in React Server
Components (RSC) within hours of it becoming public knowledge. The
vulnerability in question is CVE-2025-55182 (CVSS score: 10.0), aka
React2Shell, which allows unauthenticated remote code execution. It
has been addressed in React versions 19.0.1, 19.1.2, and 19.2.1.
According
Read more https://thehackernews.com/2025/12/chinese-hackers-have-started-exploiting.html

