PyTorch Users at Risk: Unveiling 3 Zero-Day PickleScan Vulnerabilities
December 2, 2025 | 14 min read
December 5, 2025
5 min read
JFrog continues to track and provide updates on React2Shell at research.jfrog.com. What happened A critical React vulnerability - CVE-2025-55182 (and the corresponding CVE-2025-66478 in Next.js) was published by the React maintainers. The vulnerability was named "React2Shell" by the original researcher as it leads to arbitrary code execution by remote (possibly unauthenticated) attackers. A remote attacker could craft a…
December 2, 2025 | 14 min read
November 24, 2025 | 9 min read
November 13, 2025 | 5 min read
November 11, 2025 | 10 min read
November 4, 2025 | 12 min read
October 28, 2025 | 6 min read
October 21, 2025 | 10 min read
October 16, 2025 | 7 min read
October 15, 2025 | 5 min read
September 19, 2025 | 4 min read