CVE-2025-55182 (nicknamed React2Shell): Is it possible to avoid running Coolify or containers as root
#7577
ebrearley
started this conversation in
Improvement Requests
Replies: 1 comment
-
|
It will certainly be possible in the future but upgrading is the only real solution. Even with |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
People running React with server components are vulnerable to full container takeovers through CVE-2025-55182 (rated 10.0 / 10). We had our environment keys leaked through this (we didn't update in time and the Fastly WAF mitigation didn't work, nor did Vercels or Cloudflares).
There are botnets exploiting this vulnerability and installing crypto miners in systems running as root (one example of this has been posted on Reddit https://www.reddit.com/r/nextjs/comments/1pgiaj3/i_got_hacked_and_traced_how_much_money_hacker/)
Would it be possible to remove the need to run everything as
root?Beta Was this translation helpful? Give feedback.
All reactions