
π₯ React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478
π¨ Critical RCE in React Server Components & Next.js π¨
Professional Red Team Toolkit for CVE-2025-55182 Detection & Exploitation
π Features β’ β‘ Quick Start β’ π Documentation β’ π€ Connect
React2Shell is a critical unauthenticated Remote Code Execution (RCE) vulnerability affecting React Server Components (RSC) and Next.js applications.
| CVE ID | Component | CVSS Score | Impact |
|---|---|---|---|
| CVE-2025-55182 | React Server Components | 10.0 π΄ | Complete Server Takeover |
| CVE-2025-66478 | Next.js Server Actions | 10.0 π΄ | Full System Compromise |
// Attacker sends malicious Flight protocol payload
POST / HTTP/1.1
Next-Action: exploit
Content-Type: multipart/form-data
{"__proto__": "pollution", "then": "gadget_chain"}
β
Unsafe Deserialization
β
Prototype Pollution
β
π₯ Remote Code Execution π₯
|
π Successful RCE Exploitation
Command execution via React2Shell vulnerability |
π₯ Vulnerability Confirmation
Server compromise through Flight protocol |
β οΈ These screenshots demonstrate real exploitation in controlled environments
Use responsibly and only with proper authorization
This repository contains 4 professional-grade tools for CVE-2025-55182 detection and exploitation:
π Nuclei TemplateAdvanced Scanner β
5 Payloads |
π Shodan ScannerTarget Discovery β
Automated Search |
π» Bash ExploitCLI Framework β
8 Predefined Payloads |
π§ Burp ExtensionManual Testing β
30+ Payloads |
# Clone the repository
git clone https://github.com/cybertechajju/R2C-CVE-2025-55182-66478.git
cd R2C-CVE-2025-55182-66478
# Install Python dependencies
pip install -r requirements.txt
pip install -r exploits/requirements.txt
# Scan single target
nuclei -t nuclei-templates/cve-2025-55182.yaml -u https://target.com
# Scan multiple targets
nuclei -t nuclei-templates/cve-2025-55182.yaml -l targets.txt
# Interactive wizard mode
python exploits/shodan_scanner_advanced.py
# Or with API key directly
python exploits/shodan_scanner_advanced.py --api YOUR_SHODAN_API_KEY
# Interactive mode
bash exploits/scanner_advanced.sh -i
# Quick exploitation
bash exploits/scanner_advanced.sh -d https://target.com -p 2
burp-extension/React2Shell_Burp.pycve-2025-55182/
βββ π nuclei-templates/ # Nuclei YAML templates
β βββ cve-2025-55182.yaml # Advanced detection template
βββ π exploits/ # Exploitation tools
β βββ shodan_scanner_advanced.py # Shodan mass scanner
β βββ scanner_advanced.sh # Bash exploitation framework
β βββ requirements.txt # Python dependencies
βββ π burp-extension/ # Burp Suite extension
β βββ React2Shell_Burp.py # Main extension (30+ payloads)
β βββ payloads.json # Payload library
β βββ detection_rules.json # Detection patterns
βββ π burp bechek/ # BCheck files for Burp Scanner
β βββ CVE-2025-55182-React2Shell-Active.bcheck
β βββ CVE-2025-66478-NextJS-React2Shell-Active.bcheck
βββ π README.md # This file
41 * 271 = 11111 (zero false positives)