ZAP Adds Built-in Detection for React2Shell Vulnerability

The latest release of Zed Attack Proxy (ZAP) includes mechanisms to detect the critical‐severity vulnerability known as React2Shell (CVE-2025-55182 / CVE-2025-66478), which allows remote code execution in servers using React Server Components — including apps built with Next.js. The announcement says ZAP now offers two detection methods: a passive scan via the Retire.js add-on, and a new “Active Scan Rules” check specifically for React2Shell. Because the vulnerability is so serious and widespread, the team promoted the detection rule directly to “release” quality, noting it makes only a single request per host while offering a highly reliable check. 

https://www.zaproxy.org/blog/2025-12-05-react2shell-detection-with-zap/

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities