Defending against the CVE-2025-55182 (React2Shell)

Hello,
Does anyone know anything about UiPath security in relation to the vulnerability in React Server Components React2Shell (CVE-2025-55182) at UiPath?
Does UiPath use vulnerable React, Next.js, or similar components in Vesion AutomationSuite 2024.10 or 2025.10?

Thank you for your help.

Hi @thomas.eichenberger ,

UiPath has reviewed CVE-2025-55182 (React2Shell) and confirmed that UiPath products, including AutomationSuite 2024.10 and 2025.10, are not affected. UiPath does not use the vulnerable React Server Components or Next.js in a way that exposes this issue.

1 Like

Hi @thomas.eichenberger

UiPath has not published any advisory confirming impact from CVE-2025-55182.

Automation Suite 2024.10 / 2025.10 are not reported as affected according to the UiPath Trust Center.

for reference: https://trust.uipath.com/

Cheers

1 Like

Hi @Maheep_Tiwari
Thank you for pointing that out.
Where exactly does UiPath publish this information? I only found something about React4Shell.

Hi @nishiijain2000
Everything I need to know in one post. Perfect! Now I know where to look it up (@Maheep_Tiwari my question to you is no longer necessary ;-))

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.