ZAP Adds Built-in Detection for React2Shell Vulnerability
The latest release of Zed Attack Proxy (ZAP) includes mechanisms to detect the critical‐severity vulnerability known as React2Shell (CVE-2025-55182 / CVE-2025-66478), which allows remote code execution in servers using React Server Components — including apps built with Next.js. The announcement says ZAP now offers two detection methods: a passive scan via the Retire.js add-on, and a new “Active Scan Rules” check specifically for React2Shell. Because the vulnerability is so serious and widespread, the team promoted the detection rule directly to “release” quality, noting it makes only a single request per host while offering a highly reliable check.
https://www.zaproxy.org/blog/2025-12-05-react2shell-detection-with-zap/
Comments
Post a Comment