Black Hat Asia 2026 | Discovering React2Shell: JavaScript’s Long-Awaited Deserialization Flight-mare

MediaVideo

Millions of exposed sites. Over a billion attack attempts in a week. When you hear “Insecure Deserialization”, you usually think of legacy Java apps, PHP behemoths, or crusty .NET projects – not the most popular modern JavaScript framework.

React2Shell (CVE-2025-55182) challenged this, proving that “this code is widely used and battle-tested, so I’m sure it’s secure” doesn’t mean we can’t teach this new dog some old deserialization tricks.

This Briefing will cover the novel attack surface of deserializing complex JavaScript objects and building sophisticated exploits that abuse quirks of the language, V8 engine, and Node.js runtime. As well as detailing how I discovered React2Shell, I’ll also share the impact of AI hallucinations, the double-edged sword of day-zero defenses, and lessons learned across the industry.

Lachlan Davidson | Security Innovation Lead, Carapace

https://blackhat.com/asia-26/briefings/schedule/index.html#discovering-react2shell-javascripts-long-awaited-deserialization-flight-mare-51580Black HatRead More