Weaponizing And Defending The React Flight Protocol: Deserialization Sinks In RSCs
Researchers uncovered that the Flight stream, which powers React Server Components in frameworks like Next.js, treats specially‑prefixed strings as executable directives rather than plain data. By crafting a malicious payload that manipulates the “$” prefixes—particularly the $F server‑action reference and the $@ raw chunk handle—an attacker can force the client runtime to resolve arbitrary objects, traverse prototype chains, and ultimately invoke server‑side code without authentication. The vulnerability was disclosed as CVE‑2025‑55182 in December 2025, assigned a CVSS 10.0 rating, and quickly entered CISA’s Known Exploited Vulnerabilities list after Sysdig linked real‑world exploitation to a North Korean group deploying file‑less implants via the Ethereum blockchain. The exploit required only a single HTTP request to a Server Function endpoint, delivering shell access to the victim host.
The flaw underscores a broader pattern where modern JavaScript frameworks expose rich, stateful wire protocols that blur the line between data transport and code execution. Similar deserialization issues have plagued languages like Java and Ruby for years, but the rise of “zero‑bundle” architectures—React Server Components, Remix loaders, and Astro islands—means more developers rely on opaque streaming formats without inspecting the payloads. The Flight protocol’s line‑delimited rows and reference system, while enabling fine‑grained streaming, inadvertently provide an attack surface comparable to traditional binary deserialization libraries. Competitors such as SolidJS and SvelteKit have avoided this pitfall by keeping server‑client contracts JSON‑only, suggesting a potential differentiator in security‑focused marketing.
Going forward, teams must treat Flight data as untrusted input. Immediate mitigations include strict schema validation on every Server Action, isolating server‑only packages to prevent accidental exposure, and reinforcing CSRF tokens beyond the defaults provided by Next.js. Longer‑term defenses may involve tightening the Taint API, configuring WAF rules to block suspicious “$” prefixed strings, and contributing upstream patches that remove raw chunk exposure ($@) from the public protocol. Monitoring for new exploits that leverage prototype pollution or lazy‑component loading will be essential, especially as the ecosystem expands the use of Server Components in production.
Key Takeaways
React2Shell (CVE‑2025‑55182) grants unauthenticated RCE by abusing Flight’s “$” prefix resolution.
The vulnerability was actively exploited by a North Korean threat group using Ethereum‑based file‑less implants.
Mitigations require schema validation, server‑only packaging, and hardened CSRF measures for Server Actions.
Developers should treat Flight streams as hostile data and consider upstream changes to eliminate raw chunk exposure.
About the Source
This analysis is based on reporting by Smashing Magazine. Here is a short excerpt for context:
While React Server Components rely on the custom Flight protocol to stream interactive UIs, this same mechanism introduces powerful deserialization sinks that attackers can exploit. Durgesh Pawar breaks down the mechanics behind the CVSS 10.0 “React2Shell” vulnerability to show how protocol manipulation can lead to remote code execution.Read the original at Smashing Magazine