React.js-Lücke wird aktiv ausgenutzt

09. Dezember 2025

Eine Sicherheitslücke in der Javascript-Bibliothek react.js wird aktiv von China ausgenutzt

Just days after the disclosure of the React2Shell critical vulnerability, tracked as CVE-2025-55182, threat actors are actively exploiting the flaw in react.js in the wild.

The vulnerability carries a CVSS v3.1 score of 10, the highest possible severity rating.

Amazon Web Services (AWS) has confirmed that threat groups including Earth Lamia and Jackpot Panda, both linked to Chinese state interests, are among those launching exploitation attempts.

Earth Lamia is known for exploiting web application vulnerabilities to target organizations across Latin America, the Middle East and Southeast Asia.

The group has historically targeted sectors across financial services, logistics, retail, IT companies, universities, and government organizations.

Jackpot Panda is primarily targets entities in East and Southeast Asia.


Ähnliche Beiträge