Last updated 8th December 2025
Update 2025-12-08
Critical Software Vulnerability Alert
A critical vulnerability has been discovered in components related to the React development framework and applications built using it, such as Next.js.
- This flaw is considered high-risk and allows unauthorized access to servers.
- Security experts have named this flaw “React2Shell,” and it is currently being actively exploited by malicious actors globally.
- You can find the public security bulletin here for reference: React2Shell (CVE-2025-55182): Critical React Vulnerability | Wiz Blog
Our Security Status (Crucial Update)
Our Security and Engineering teams have completed an immediate and thorough evaluation of all active product lines and platforms in relation to this vulnerability.
- Our Current Products Are Not Affected: Our analysis confirms that none of our currently deployed customer-facing products or internal systems are exposed to the React2Shell vulnerability.
- Products Under Development Are Patched: All products currently in the development pipeline have been reviewed and are being built with the necessary security patches already applied.
This means there is no risk to the stability or security of our services from this specific vulnerability.
Our Ongoing Commitment
Our technical teams are treating this matter with the highest urgency:
- Continuous Monitoring: We are continuously monitoring our environments for any signs of related malicious activity globally.
- Proactive Defense: We remain committed to proactively assessing new threats and ensuring the security of our infrastructure.