Vulnerabilità ed exploit · Furto di credenziali

Next.js React2Shell Exploit Automates AI and Cloud Credential Theft

React2Shell exploitation has escalated from remote code execution to automated mass credential harvesting on vulnerable Next.js React Server Components. Attackers now extract AI API keys, cloud tokens, SSH keys, and environment secrets from at least 766 compromised servers worldwide without further interaction after initial exploitation. This turns each infected host into a gateway for deeper access to cloud platforms, AI services, and SSH targets, extending the blast radius beyond the web application itself. Patch vulnerable React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 immediately. Treat all secrets accessible from affected hosts as compromised, as remediation of the host alone does not prevent follow-on attacks using stolen credentials.

5 fonti · 7 apr

CVE-2025-55182

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 10 CRITICAL: a pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0… Impiego noto in campagne ransomware. EPSS 66% (99º percentile).

Data di correzione federale CISA 12 dic · data superata

Cronologia

Fonti

Part of the PlainSec briefing for 2026-04-04

Every edition of this story: Next.js React2Shell Exploit Automates AI and Cloud Credential Theft

Altro da oggi