We want to reassure you that the Bucketlist Rewards platform is not affected by the React2Shell (CVE-2025-55182) vulnerability.
A critical security vulnerability, designated CVE-2025-55182 and known as “React2Shell,” was recently discovered in React’s react-server-dom-webpack versions 19.0.0 through 19.2.0 package. This vulnerability represents an unauthenticated remote code execution exploit and has been assigned the maximum CVSS severity rating of 10.0.
We have confirmed that our application does not utilize any of the affected React packages, and no action is required from you at this time.
The security of our platform and the protection of your data remain our highest priorities. We continuously monitor emerging security threats and maintain proactive measures to ensure the integrity of our systems.
Should you have any questions or concerns regarding this matter, please don’t hesitate to contact our support team.
For technical details about CVE-2025-55182, please visit this link.