Automated React2Shell vulnerability patching is now available
Not a pilot. Vercel just automated critical vulnerability patching across React and Next.js projects.

Why it matters
Vercel's Agent now automatically detects and patches the React2Shell RCE vulnerability (CVE-2025-55182) affecting React 19 and Next.js, generating verified pull requests at no cost. This shifts security vulnerability response from manual to autonomous for the millions of developers on Vercel's platform.
The key facts
6 to knowReact2Shell (CVE-2025-55182) is a critical RCE in React Server Components affecting React 19 and Next.js
Vercel Agent automatically detects vulnerable packages and generates pull requests with patched upgrades
Feature includes isolated Sandbox environment execution and verification of updates
Preview links auto-generated with PRs for manual validation
Available at no cost to all Vercel users
Applies to React, Next.js, and related RSC package ecosystems
Go to the source
Vercel Blogvercel.com
Publisher excerpt: Vercel Agent now detects vulnerable packages in your project, and automatically generates pull requests with fixes to upgrade them to .patched versions Powered by Vercel's , these auto-fix upgrades are available at no cost and help teams stay secure with minimal manual effort.self-driving…