Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182 — Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement), interactive reverse shell, and a complete vulnerable lab for studying Prototype Pollution and Insecure Deserialization in React Server Components. | Kitploit
Tools/GitHubGitHub/devianntsec/cve-2025-55182
Exploit FrameworksVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationPenetration TestingPapers & ResearchLearning & EducationRemote Access Tool
Payload Development
Labs & Practice
GitHubdevianntsec/cve-2025-55182

CVE-2025-55182

View Repository
1145 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement), interactive reverse shell, and a complete vulnerable lab for studying Prototype Pollution and Insecure Deserialization in React Server Components.

Share

CVE-2025-55182 — React2Shell: Advanced Exploit & Master's Thesis Research

Platform Language License: MIT Research CVSS

Deserialization of Untrusted Data + Prototype Pollution in React Server Components
Unauthenticated Remote Code Execution via Next.js Server Actions
Affected: React 19.0.0 - 19.2.0 · Patch: React 19.0.1 / 19.1.2 / 19.2.1 (December 3, 2025)


Demonstration of the advanced exploit - RCE basic commands, interactive shell, and multiple attack vectors against a vulnerable Next.js application

Description

This repository contains my Master's Thesis research on CVE-2025-55182, a Critical (CVSS v3.1: 10.0) Remote Code Execution vulnerability in React Server Components.

The vulnerability originates from an unsafe deserialization mechanism in the React Flight protocol. When processing Server Actions, Next.js deserializes incoming multipart payloads without proper validation. An attacker can craft a malicious payload that pollutes the prototype chain and injects arbitrary JavaScript, which executes on the server via the Function constructor (and subsequently via child_process.execSync()).

Note on CVE-2025-66478: Vercel issued a parallel CVE to track the Next.js-specific impact of this same vulnerability. Because Next.js bundles React in a vendored manner, many dependency scanners do not automatically detect it as vulnerable. The US National Vulnerability Database (NVD) officially rejected CVE-2025-66478 as a duplicate of CVE-2025-55182, though it continues to be referenced in Vercel's own security advisory.

Follow-on vulnerabilities: The React team subsequently disclosed two additional issues present in the initial patch versions (19.0.1, 19.1.2, 19.2.1): CVE-2025-55184 (Denial of Service, CVSS 7.5) and CVE-2025-55183 (Source Code Exposure, CVSS 5.3). Users should upgrade to 19.0.2, 19.1.3, or 19.2.2 to address all three.

My Contribution

AspectDescription
Four attack modulesDelete projects, deface website, steal environment variables, shutdown servers
Interactive shellPersistent shell with special commands and restoration capabilities
Stable exfiltrationLine-by-line reading to bypass HTTP header size limitations
Restoration scriptSafe laboratory restoration after attacks
Academic documentationRoot cause, payload breakdown, and vulnerability timeline

Repository Structure

CVE-2025-55182/
├── README.md                        # This file
├── LICENSE                          # MIT License
│
├── exploit/
│   ├── exploit-explanation.md       # Exploit usage documentation
│   └── react2shell.py               # Main exploit — 4 attack modules + interactive shell
│
├── vulnerable-app/                  # Vulnerable Next.js application
│   ├── README.md                    # Original vulnapp credits
│   ├── package.json                 # React 19.0.0 (vulnerable)
│   ├── app/                         # Application source code
│   ├── curl_id.sh                   # Original exploit script (by zack0x01)
│   └── scripts/
│       └── restore.sh               # Restoration script (my contribution)
│
└── docs/
    ├── screenshots/                 # Exploitation demonstrations
    │   ├── 01-app-initial.png
    │   ├── 02-rce-basic.png
    │   ├── 03-interactive-shell.png
    │   ├── 04-no-payload.png
    │   ├── 05-delete-result.png
    │   ├── 06-deface.png
    │   ├── 07-shutdown-servers.png
    │   ├── 08-restore-from-script.png
    │   └── 09-restore-from-interactive-shell.png
    │
    └── analysis/
        ├── 01-root-cause.md         # Vulnerability root cause analysis
        ├── 02-payload-breakdown.md  # Payload structure and execution flow
        └── 03-timeline.md           # CVE timeline

Quick Start

Prerequisites

  • Node.js 18+ and npm
  • Python 3.9+
  • Vulnerable Next.js application (provided in vulnerable-app/)
  • Isolated VM recommended for testing

Step 1 — Start the vulnerable application

cd vulnerable-app
npm install --legacy-peer-deps
npm run dev
# App available at http://localhost:3000

Step 2 — Run the exploit

cd ../exploit

# Check if target is vulnerable
python3 react2shell.py -u http://localhost:3000 --check

# Execute single command
python3 react2shell.py -u http://localhost:3000 -c "whoami"

# Interactive shell mode
python3 react2shell.py -u http://localhost:3000 -i

Attack Modules

ModuleCommandDescriptionImpact
Delete Projects--delete-projectsDeletes all projects from dashboardData destruction
Deface--deface "message"Replaces the main pageDefacement
Steal Environment--steal-envSteals environment variablesExfiltration
Shutdown Servers--shutdown-serversShuts down all serversDenial of Service

Technical Overview

Vulnerability Root Cause

React Server Components use a custom serialization/deserialization mechanism (the "Flight" protocol) to send component data from server to client. When processing server actions, the server deserializes incoming payloads without proper validation.

The core flaw is behavioral trust: the deserializer checks typeof obj.then === 'function' to identify Promises, without verifying that the property belongs directly to the object. This allows an attacker to poison Object.prototype.then, making every plain object appear as a thenable.

An attacker can craft a malicious payload that:

  1. Pollutes the prototype chain using __proto__:then
  2. Redirects resolution to the Function constructor via $1:constructor:constructor
  3. Executes arbitrary JavaScript via new Function(_prefix)
  4. Runs system commands via process.mainModule.require('child_process').execSync()
  5. Exfiltrates output through the X-Action-Redirect HTTP response header
User-mode (unauthenticated)
  │
  ├─ POST / (Next.js Server Action endpoint)
  │    ├─ Headers: Next-Action: x
  │    └─ Multipart body with malicious JSON
  │
  └─ React Flight deserializer processes payload
       └─ Prototype pollution via __proto__:then
            └─ Function constructor reached via $1:constructor:constructor
                 └─ new Function(_prefix) executes attacker's JavaScript
                      └─ execSync() runs system command
                           └─ Output embedded in NEXT_REDIRECT error
                                └─ Next.js converts to X-Action-Redirect header

Scope Clarification

The vulnerability affects any Next.js application using the App Router with React Server Components — the default configuration since Next.js 14. Explicitly defined Server Actions are not required; the mere presence of the affected RSC packages is sufficient.

Why It Matters

This vulnerability allows an unauthenticated attacker to:

  • Execute arbitrary commands on the server
  • Steal environment variables and credentials
  • Modify or delete application data
  • Use the server as a pivot point for further attacks

Attack Chain

Download Tool