
Threat Talks · 2026-03-24 · 15 min
Log4j caught everyone off guard. React2Shell might be doing the same right now. Across thousands of React apps, exposure is already baked in - accelerated by vibe coding and shipped without scrutiny. In some cases, one request is all it takes. React2Shell turns that exposure into remote code execution in React and Next.js environments -triggered by a single HTTP POST request. In this episode of Threat Talks, host Rob Maas and SOC analyst Yuri Wit break down how React2Shell works, why it’s more serious than it looks, and what makes it so easy to exploit. The risk is significant, and what makes it worse is how little attention it’s getting. As developers increasingly rely on AI-generated code, applications are being shipped faster - but not always with full visibility into how components behave. That creates blind spots attackers can take advantage of, especially when serialization and deserialization flaws are involved. We cover how React2Shell works, how attackers exploit serialization and deserialization flaws, and what actions you need to take now to reduce risk.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.