elastic
high
kql
React2Shell Network Security Alert
This rule identifies network security alerts related to CVE-2025-55182 exploitation attempts from different network security
integrations. CVE-2025-55182 is a critical remote code execution vulnerability in React Server Components (RSC) Flight protocol.
The vulnerability allows attackers to execute arbitrary code on the server by sending specially crafted deserialization payloads
that exploit prototype chain traversal to access the Function constructor.