The bug, tagged as CVE-2025-55182 and referred to colloquially as React2Shell, was reported to Meta by researcher Lachlan Davidson on November 29 and publicly disclosed on Wednesday, when a fix was rolled out.
First seen on therecord.media
Jump to article: therecord.media/chinese-hackers-exploiting-react2shell-vulnerability-amazon
![]()

