Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
react2shell-scanner — Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix, SARIF output, and CI/CD integrations. | Kitploit
Tools/GitHubGitHub/gensecaihq/react2shell-scanner
Vulnerability ScannersContainer SecurityCode AnalysisWeb SecurityDevSecOpsSecret DetectionSupply Chain Security
GitHubgensecaihq/react2shell-scanner

react2shell-scanner

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix, SARIF output, and CI/CD integrations.

View RepositoryWebsite
597189 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

react2shell-guard

Security scanner for CVE-2025-55182 - a critical (CVSS 10.0) unauthenticated Remote Code Execution vulnerability in React Server Components.

⚠️ DISCLAIMER

This is a security scanner, NOT an exploit tool. It is designed to help developers and security teams identify vulnerable dependencies in their projects.

This is a community-driven open source project provided "AS IS" without warranty of any kind, express or implied. The authors and contributors are not responsible for any damages or security incidents arising from the use of this tool.

Use at your own risk and responsibility. Always verify findings manually and follow your organization's security policies. If you discover any issues, bugs, or have suggestions, please contribute back to help improve the project for everyone.

🤝 CONTRIBUTORS WANTED

This project is actively looking for testers and contributors! Whether you want to report bugs, suggest features, improve documentation, or submit code - all contributions are welcome. Check out our Contributing Guide to get started.

Acknowledgments

This project exists to help the community respond to CVE-2025-55182. We acknowledge and thank:

  • Lachlan Davidson (react2shell.com) - For discovering and responsibly disclosing the React Server Components vulnerability (CVE-2025-55182) on November 29th, 2025. The security community owes him gratitude for his diligence in identifying this critical flaw and working with the React and Next.js teams to ensure patches were available. His efforts have helped protect countless applications and users worldwide. See his original PoC for technical details.

Quick Start

1. Instant Scan (No Installation)

The fastest way to check if your project is vulnerable:

npx react2shell-guard .

That's it! This will scan your current directory and show results immediately.

2. Scan a Specific Project

npx react2shell-guard /path/to/your/project

3. Auto-Fix Vulnerabilities

Found vulnerabilities? Fix them automatically:

# Preview what will be changed
npx react2shell-guard fix --dry-run

# Apply fixes
npx react2shell-guard fix

# Apply fixes and reinstall dependencies
npx react2shell-guard fix --install

4. Scan Live URLs

Check if a deployed application is vulnerable:

npx react2shell-guard scan-url https://your-app.com

5. Verify Patch Was Applied

Confirm your deployed fix is working:

npx react2shell-guard verify-patch https://your-app.com

6. Scan Container Images

Check if your Docker images contain vulnerable packages:

npx react2shell-guard scan-image myapp:latest

7. Create Fix PR (GitHub)

Automatically create a GitHub PR to fix vulnerabilities:

npx react2shell-guard create-pr --dry-run  # Preview
npx react2shell-guard create-pr            # Create PR

What is CVE-2025-55182?

On November 29th, 2025, security researcher Lachlan Davidson discovered and responsibly disclosed a critical vulnerability in React Server Components. The flaw exists in how React decodes payloads sent to React Server Function endpoints, allowing unauthenticated attackers to achieve remote code execution on affected servers without any user interaction.

CVE-2025-55182 is rated CVSS 10.0 (Critical) and affects React Server Components (RSC) and frameworks using the RSC "Flight" protocol.

Affected Packages:

  • react-server-dom-webpack 19.0.0, 19.1.0-19.1.1, 19.2.0
  • react-server-dom-parcel (same versions)
  • react-server-dom-turbopack (same versions)
  • next 15.0.0-15.0.4, 15.1.0-15.1.8, 15.2.0-15.2.5, 15.3.0-15.3.5, 15.4.0-15.4.7, 15.5.0-15.5.6, 16.0.0-16.0.6

More Information:

  • React Security Advisory
  • Wiz Research

Installation (Optional)

For frequent use, install globally:

npm install -g react2shell-guard

Then use without npx:

react2shell-guard .

Usage Guide

Basic Scanning

# Scan current directory
react2shell-guard .

# Scan specific directory
react2shell-guard /path/to/project

# Scan and ignore certain paths
react2shell-guard . --ignore-path "examples/**" "test/**"

Output Formats

# Human-readable text (default)
react2shell-guard .

# JSON output (for scripting)
react2shell-guard . --json

# SARIF output (for GitHub Security tab)
react2shell-guard . --sarif

# HTML report (standalone, shareable)
react2shell-guard . --html report.html

CLI Options

OptionDescription
--jsonOutput results as JSON
--sarifOutput results as SARIF 2.1.0
--html <file>Generate standalone HTML report
--no-exit-on-vulnDon't exit with code 1 when vulnerabilities found
--ignore-path <patterns>Paths to ignore (e.g., examples/**)
--debugEnable debug output

Exit Codes

CodeMeaning
0No vulnerabilities found
1Vulnerabilities detected
2+Fatal error

Live URL Scanning

Scan live endpoints to detect if they are vulnerable:

# Scan a single URL
react2shell-guard scan-url https://example.com

# Batch scan from a file (one URL per line)
react2shell-guard scan-url urls.txt --list

# With options
react2shell-guard scan-url https://example.com --timeout 5000 --json

How Live URL Scanning Works

The scanner uses passive fingerprinting to detect vulnerable React Server Components endpoints without exploiting the vulnerability:

  1. Probe Request: Sends a crafted POST request simulating an RSC Server Action call with a minimal payload:

    • Uses multipart/form-data content type with RSC-like data structure
    • Includes Next-Action header to trigger Server Action processing
  2. Response Analysis: Analyzes the HTTP response for vulnerability signatures:

    • Checks for HTTP 500 status code (error response)
    • Matches response body against RSC Flight protocol error patterns:
      • ^[0-9]+:E{ - RSC Flight protocol error format
      • "digest":"...RSC - RSC digest in error responses
      • ReactServerComponentsError - React error class names
      • text/x-component.*error - Component error content type
  3. Non-Destructive: This is purely a detection mechanism - it does not execute any malicious payload or exploit the vulnerability. The probe uses benign data that triggers error responses on vulnerable servers but causes no harm.

Note: A positive detection means the server is running a vulnerable version and returned an RSC-specific error signature. It does NOT mean the server was exploited.

URL Scanner Options

OptionDescription
--listTreat target as a file containing URLs
--threads <n>Number of concurrent threads (default: 10)
--timeout <ms>Request timeout in milliseconds (default: 10000)
--jsonOutput results as JSON
--skip-ssl-verifySkip SSL certificate verification
--verboseShow all results including non-vulnerable hosts

Patch Verification

Verify if a target has been patched against the vulnerability:

# Verify patch status (runs multiple scans for accuracy)
react2shell-guard verify-patch https://example.com

# With JSON output
react2shell-guard verify-patch https://example.com --json

How Patch Verification Works

Download Tool