The recently disclosed React2Shell (CVE-2025-55182) vulnerability is already being exploited in the wild, with over 30 organizations breached and more than 77,000 Internet-facing IP addresses confirmed vulnerable.
Because React2Shell is actively exploited and can appear across many applications and environments, you need a way to identify exposure quickly and at scale.
Over the weekend, we added support for this vulnerability.
Escape DAST now provides continuous, automated detection of React2Shell at scale across all your applications and environments.
To give teams complete visibility into both vulnerability presence and real-world exploitability, we’ve introduced two dedicated checks:
This check identifies whether the underlying JavaScript runtime is vulnerable to the core React2Shell issue.
Benefit: Quickly determine which assets are at risk of the vulnerability itself
This simulates a full server compromise by testing whether remote command execution (system-level shell access) is achievable.
Benefit: Confirms whether an attacker could escalate to total server takeover

To safely and reliably confirm RCE, Escape uses controlled payloads that spawn a subprocess executing a harmless expression, for example:
echo $numberA + $numberB
Escape then inspects the application’s response for the computed result, proving whether arbitrary commands can execute without performing any destructive action. This ensures both zero-risk validation and high-confidence detection.
Escape’s detection is designed to be safe and non-destructive. Some environments may block or filter subprocess calls, which can lead to false negatives. To reduce this, Escape runs multiple payload variants and provides two separate checks—one for vulnerability presence and one for full Shell RCE—offering high-confidence detection across diverse environments.
Two complementary checks (JS RCE + Shell RCE) reduce the chance of missing exploitable cases.
Escape provides clear, reproducible evidence whenever React2Shell is exploitable.
By using safe, controlled payloads that trigger the server to execute a harmless command, Escape can confirm whether remote code execution actually occurred. The result is shown directly in the scan findings, giving teams:
- High-confidence confirmation of real RCE
- A precise payload/response pair demonstrating the exploit
- Clear separation between vulnerability present and vulnerability exploitable
This allows security teams to triage React2Shell based on verified impact:

Each finding includes detailed remediation guidance tailored to your environment. Escape highlights:
- How to validate and reproduce the vulnerability associated with the React2Shell CVE-2025-55182
- Recommended remediation steps
For all organizations, we recommend implementing a WAF rule to block exploitation immediately (if not already done) and updating the React versions in use to 19.0.1, 19.1.2, and 19.2.1, which are not vulnerable.
With these new checks, organizations can immediately:
- Detect React2Shell vulnerabilities anywhere in their environment
- Understand which systems are merely exposed versus fully exploitable
- Prioritize patching and mitigation based on true attacker impact
- Maintain continuous monitoring as environments change
By combining proof of exploitation with actionable fixes, Escape enables security and engineering teams to prioritize and remediate React2Shell quickly and confidently—across all applications and environments.