Windows Suspicious React or Next.js Child Process: endpointEndpointNoneversion:5
This analytic detects Windows processes such as cmd.exe, PowerShell, and common Windows LOLBINs being spawned by React or Next.js application servers.
In the context of CVE-2025-55182 / React2Shell / CVE-2025-66478 for Next.js, successful exploitation can lead to arbitrary JavaScript execution on the server, which in turn is used to invoke Node's child_process APIs (for example child_process.execSync) to run OS-level commands.
This detection focuses on suspicious child processes where a Next/React server process spawns an uncommon process.
Such activity might be a strong indicator of exploitation of the aforementioned vulnerability.
Linux Suspicious React or Next.js Child Process: endpointEndpointNoneversion:4
This analytic detects Linux processes such as sh, bash, and common Linux LOLBINs being spawned by React or Next.js application servers.
In the context of CVE-2025-55182 / React2Shell / CVE-2025-66478 for Next.js, successful exploitation can lead to arbitrary JavaScript execution on the server, which in turn is commonly used to invoke Node's child_process APIs (for example child_process.execSync) to run OS-level commands.
Public proof-of-concept payloads and observed in-the-wild exploit traffic show patterns where the vulnerable React Server Components handler triggers process.mainModule.require('child_process').execSync() to execute binaries such as ping, curl, or arbitrary shells on the underlying host.
This detection focuses on suspicious child processes where a Next/React server process spawns an uncommon process.
Such activity might be a strong indicator of exploitation of the aforementioned vulnerability.
Cisco Secure Firewall - React Server Components RCE Attempt: endpointEndpointNoneversion:7
This analytic detects exploitation activity of CVE-2025-55182 using Cisco Secure Firewall Intrusion Events.
It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where Snort signature 65554 (React Server Components remote code execution attempt) is triggered
If confirmed malicious, this behavior could be indicative of a potential exploitation of CVE-2025-55182.