React Server Components Remote RCE Exploitation Tool is a security testing tool specifically designed for remote code execution vulnerabilities in React Server Components and Next.js frameworks. It provides a graphical user interface and supports multiple attack modes and batch detection capabilities.
⚠️ Disclaimer: This tool is intended for authorized security testing and CTF competitions only. Any use for illegal attacks is strictly prohibited. The user shall bear all consequences arising from the use of this tool.
🎯 Vulnerability Scope
Affected React Server Versions
- React Server 19.0.0
- React Server 19.0.1 (Note: Some early patches do not fully cover)
- React Server 19.1.* (All 19.1.x versions)
- React Server 19.2.0
Affected Next.js Versions
- Next.js v15.0.0 - v15.0.4
- Next.js v15.1.0 - v15.1.8
- Next.js v15.2.x - v15.5.6
- Next.js v16.0.0 - v16.0.6
- Next.js v14.3.0-canary.77 and later Canary versions
Other Affected Components
- Dify - AI application development platform
- NextChat - Chat application framework
- Other applications built on affected versions of React Server Components or Next.js
Note: If your application uses any of the versions listed above, it is recommended to upgrade to a secure version immediately or take appropriate protective measures.
✨ Features
🎯 Core Features
- Vulnerability Detection: Quickly detect whether the target has the React Server Components / Next.js RCE vulnerability
- Command Output: Execute system commands directly and obtain output results
- Memory Shell Injection: Inject a persistent webshell on the target server
- Reverse Shell: Obtain an interactive shell on the target system
- Batch Scanning: Support batch detection of multiple target URLs to quickly identify vulnerable systems
🔧 Auxiliary Features
- Proxy Support: Support HTTP proxy configuration (e.g., Burp Suite) for convenient traffic analysis
- Custom Headers: Add custom HTTP headers to bypass simple protections
- Real-time Logging: Operation logs displayed in real time for easy test tracking
- Timeout Setting: Customizable request timeout to adapt to different network environments
🚀 Quick Start
Requirements
- Java 8 or later
- Windows / Linux / macOS operating system
-
Double-click to run the React Server Components 远程RCE.jar file
-
Or start via command line:
java -jar React Server Components 远程RCE.jar
-
On first launch, a disclaimer will be displayed. Please read it carefully and agree before continuing.
📋 Usage Guide
1️⃣ Basic Configuration
Before using any functionality, configure the basic information:
- Target URL: Enter the target website address (e.g.,
http://192.168.1.100:3000)
- Attack Path: The application path (default:
/apps, adjustable based on the target)
- Timeout: Request timeout in seconds (default: 30 seconds)
- Custom Headers: Optional, one per line, format
Header-Name: value
2️⃣ Vulnerability Detection
- Fill in the target URL and basic configuration
- Click the "Test Vulnerability" button
- Wait for the detection result; the tool will automatically determine if the target is vulnerable
Tip: It is recommended to perform vulnerability detection first to confirm the target is vulnerable before proceeding with further operations.
🎮 Attack Mode Details
Mode 1: Command Output
Use case: Execute system commands and view the execution results
Steps:
- Switch to the "Command Output" tab
- Enter the command to execute in the command input box (e.g.,
whoami, ipconfig, ls -la)
- Click the "Execute Command" button
- View the command execution results in the text area below
Common command examples:
- Windows:
whoami, ipconfig, dir, net user
- Linux:
whoami, ifconfig, ls -la, uname -a
Mode 2: Memory Shell Injection
Use case: Leave a persistent backdoor on the target server
Steps:
-
Switch to the "Memory Shell Injection" tab
-
Set the memory shell access path (e.g., /exec)
-
Click the "Inject Memory Shell" button
-
After successful injection, you can execute commands via:
Access: http://target-address/exec?cmd=whoami
Usage Notes:
- The memory shell is registered in the target application's memory and does not leave any files on disk
- The memory shell becomes invalid after the server restarts
- Pass the command to execute via the URL parameter
cmd
Mode 3: Reverse Shell
Use case: Obtain an interactive shell on the target system
Steps:
-
Start a listener on your local machine (e.g., using netcat):
nc -lvnp 4444
-
Switch to the "Reverse Shell" tab
-
Enter the listener IP (your machine's IP address)
-
Enter the listener port (e.g., 4444)
-
Click the "Send Reverse Shell" button
-
Go back to the netcat window and wait for the shell connection
Notes:
- Ensure the target server can reach your listener IP and port
- The firewall must allow inbound connections on the corresponding port
- In real environments, network policy restrictions may apply
Mode 4: Batch Detection
Use case: Perform vulnerability batch scanning on multiple targets
Steps:
- Switch to the "Batch Detection" tab
- Enter the list of target URLs in the text area (one per line)
- Click the "Start Scan" button
- View the scan results; the tool will mark targets that are vulnerable
⚙️ Advanced Configuration
Configuring HTTP Proxy
Used to forward traffic to packet capture tools such as Burp Suite, making it convenient to analyze requests and responses.
Configuration Steps:
- Click the top menu "Settings" → "Proxy Settings"
- Select "Enable"
- Enter the proxy host (e.g.,
127.0.0.1)
- Enter the proxy port (e.g.,
8080)
- Click "Save"
Burp Suite Configuration:
- Ensure Burp Suite's proxy listener is started
- Default listener address:
127.0.0.1:8080
- In Burp, you can intercept and modify all requests sent by the tool
Proxy Status Display:
- After configuration, the proxy status will be shown in the upper right corner of the interface
- Green means enabled, gray means not configured
🛡️ Security Recommendations
- Use only in authorized environments: Ensure you have explicit authorization before testing any target
- Do not use in production environments: Avoid causing damage to production systems
- Protect test data: Safeguard any sensitive information obtained during testing
- Comply with laws and regulations: Unauthorized penetration testing may violate the law
- CTF competition use: This tool is suitable for use in legal environments such as CTF events and training ranges
❓ Frequently Asked Questions
Q1: "No vulnerability detected" – What should I do?
Possible causes:
- The target URL is incorrect or the service is not running
- The target does not have this vulnerability
- The attack path is misconfigured
- Network unreachable or blocked by a firewall
Solutions:
- Check if the target URL is accessible normally
- Try adjusting the attack path parameter
- Check network connectivity and proxy settings
Q2: No output after executing a command?
Possible causes:
- The command executed successfully but produced no output (e.g., certain file-writing commands)
- Permissions are restricted on the target system
- Command syntax error
Solutions:
- Try executing a command with clear output (e.g.,
id)
- Check if the command syntax is correct
- Review the detailed information in the log area at the bottom
Q3: Reverse shell connection fails?
Possible causes: