Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182 — Pre-authentication RCE exploit for React Server Components (CVE-2025-55182). Targets unsafe deserialization in react-server-dom packages across multiple frameworks. | Kitploit
Tools/GitHubGitHub/cc3305/cve-2025-55182
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPayload Development
GitHubcc3305/cve-2025-55182

CVE-2025-55182

Pre-authentication RCE exploit for React Server Components (CVE-2025-55182). Targets unsafe deserialization in react-server-dom packages across multiple frameworks.

View Repository
63 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182 - React2Shell

Pre-authentication RCE in React Server Components.

Summary of the CVE

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Affected Versions

  • React Server Components packages react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack: 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • Frameworks and bundlers that include or depend on those vulnerable packages, including Next.js, React Router, Waku, Parcel RSC, Vite RSC plugin, and RedwoodSDK
  • Next.js App Router applications on 15.x, 16.x, and 14.3.0-canary.77 or later canary releases

References

  • React Security Advisory - The React Team, Dec 3 2025
  • NVD - CVE-2025-55182
  • Github POC - Maximilian Sanft, Dec 2025
  • React2Shell Scanner - Assetnote, Dec 2025
  • Public Docker PoC lab - l4rm4nd, Dec 2025
  • Docker vulnerable lab notes - Arul Kumar, Dec 5 2025
  • CVE-details - CVSS Score 10.0
Download Tool