Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Next.js Released a Scanner to Detect and Update Apps Impacted by React2Shell Vulnerability

Next.js Released a Scanner to Detect and Update Apps Impacted by React2Shell Vulnerability

Posted on December 8, 2025December 8, 2025 By CWS

A devoted command-line software, fix-react2shell-next, to assist builders instantly detect and patch the vital “React2Shell” vulnerability (CVE-2025-66478).

This new scanner provides a one-line answer to determine weak variations of Subsequent.js and React Server Elements (RSC). Mechanically apply the required safety updates included within the newest Subsequent.js launch.

Automated Detection and Patching

The software simplifies the remediation course of by recursively scanning all package deal.json information inside a mission.

subsequent.js scanner software

This design ensures it really works successfully throughout each commonplace repositories and complicated monorepos managed by npm, yarn, pnpm, or bun.

In contrast to handbook checks, which could be susceptible to human error, the scanner systematically verifies the put in variations of subsequent, react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack.

As soon as weak packages are recognized, the utility patches them to the right, safe model, as decided by the official GitHub advisory.

It then refreshes the lockfile utilizing the detected package deal supervisor to make sure the repair is correctly locked in.

For instance, it is going to routinely improve a weak Subsequent.js 15.1.0 set up on to the fastened 15.1.9 launch.

The vulnerability impacts a number of launch traces of Subsequent.js and React RSC packages, as reported by GitHub.

Builders operating any model throughout the “Affected” ranges beneath ought to improve instantly.

PackageAffected Model RangePatched VersionNext.js15.0.0 – 15.0.415.0.515.1.0 – 15.1.815.1.915.2.0 – 15.2.515.2.615.3.0 – 15.3.515.3.615.4.0 – 15.4.715.4.816.0.0 – 16.0.616.0.7React RSC19.0.019.0.119.1.0 – 19.1.119.1.2

Tips on how to Use the Scanner

Builders can run the software immediately utilizing npx. For an interactive expertise that asks for affirmation earlier than making modifications, customers can run the usual command.

For steady integration (CI) environments or automated workflows the place prompts usually are not potential, the repair flag forces the software to use patches routinely.

Conversely, groups who wish to audit their mission with out making rapid modifications can use the dry-run flag to see a report of what can be up to date.

A json flag can be accessible for scripting functions, permitting safety groups to pipe the output into different monitoring instruments. To run the interactive repair, execute the next command in your terminal: npx fix-react2shell-next.

Observe us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Apps, Detect, Impacted, Next.js, React2Shell, Released, Scanner, Update, Vulnerability

Post navigation

Previous Post: MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign
Next Post: Shanya EDR Killer Leveraged by Hackers to Clear the Way for Ransomware Infection

Related Posts

Malvertising Campaign Exploits Tax Season with EDR Attacks Malvertising Campaign Exploits Tax Season with EDR Attacks Cyber Security News
Matanbuchus Malware Downloader Evading AV Detections by Changing Components Matanbuchus Malware Downloader Evading AV Detections by Changing Components Cyber Security News
Sidewinder APT Hackers Leverage Nepal Protests to Push Mobile and Windows Malware Sidewinder APT Hackers Leverage Nepal Protests to Push Mobile and Windows Malware Cyber Security News
OpenAI Launches  ChatGPT Go Plan with Unlimited Access to GPT-5 OpenAI Launches $4 ChatGPT Go Plan with Unlimited Access to GPT-5 Cyber Security News
Chinese Cyber Threat Targets Qatar Amid Middle East Unrest Chinese Cyber Threat Targets Qatar Amid Middle East Unrest Cyber Security News
Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F5 Resolves Over 50 Security Flaws in Software
  • Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit
  • Seedworm Group Exploits Signed Binaries for Cyber Attacks
  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F5 Resolves Over 50 Security Flaws in Software
  • Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit
  • Seedworm Group Exploits Signed Binaries for Cyber Attacks
  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark