React Server Components Security
React2Shell Security Bulletin      | Vercel Knowledge Base

React2Shell Security Bulletin | Vercel Knowledge Base

12/5/2025

What this post added

This post addresses critical security vulnerabilities in React Server Components, specifically React2Shell (CVE-2025-55182) and related DoS/source code disclosure issues (CVE-2025-55184, CVE-2025-55183). It provides detailed guidance on identifying affected versions of Next.js and React, outlines manual and automated upgrade methods using `npx fix-react2shell-next` and Vercel Agent, and emphasizes the importance of Vercel's deployment protection and secret rotation for mitigation.

Read the original post ↗