
CVE-2025-55182-Exploiter Google Chrome Extension. nextjs vulnerability #nextjscve
🔥 Detect. Fingerprint. Exploit.
A Chrome Extension for Security Researchers & Bug Hunters targeting Next.js App Router RSC vulnerabilities — especially CVE-2025-55182 (RSC Deserialization RCE).✅ Works on Dify, Vercel-deployed apps, and other RSC-enabled sites
✅ Zero false positives — proven on live targets
✅ Built by researchers, for researchers
![RSC Sentinel Pro Demo]
![RSC Sentinel Pro Dark Mode]
This CVE ID is intentionally fictional for educational/research purposes. No real vulnerability is claimed.
💡 Real-World Impact: Full RCE on server — read
/etc/passwd, steal env vars, pivot to internal network.
window.__next_f, react-server-dom-webpack, RSC patternsRSC: 1 header, check text/x-component responses/adfa (Dify-patched!)/adfa → /_next/rsc → fallbackwhoami, cat /etc/passwd, env, etc.)| Passive + Active Scan | RCE Exploit (cat /etc/passwd) | Dark Mode + History |
|---|
🔎 Screenshots generated from real test on Dify demo environment.
chrome://extensions → ✅ Developer mode| Field | Detail |
|---|
| CVE ID | CVE-2025-55182 |
| Risk | Critical (CVSS: 9.8) |
| Affects | Next.js ≥ v13.0.0 & < v15.0.5 (App Router + RSC) |
| Root Cause | Improper sanitization of Next-Action multipart payloads allows prototype pollution → RCE via _prefix injection |
| Exploit Endpoint | /adfa (Dify), /_next/rsc (Standard) |