React CVE-2025-55182 (CVSS 10.0) hits crypto sites; Dec. 3 disclosure spurs exploits

React Server Components’ CVE-2025-55182, rated CVSS 10.0, is being actively exploited to drain crypto wallets across frameworks like Next.js. Attacks surged following the Dec. 3 disclosure; patches shipped in React 19.0.1, 19.1.2, and 19.2.1, with Next.js updates across 14.2.35–16.0.10. Sites should upgrade, deploy WAF rules, and review front-end code for malicious assets.