Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/ihsansencan/react2shell-cve-2025-55182
Vulnerability AnalysisExploitationWeb Application ExploitationLearning & EducationRemote Access ToolContainer Escape
GitHubihsansencan/react2shell-cve-2025-55182

React2Shell-CVE-2025-55182

* React2Shell-CVE-2025-55182

View Repository
159 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🔥React2Shell - CVE-2025-55182 / CVE-2025-66478 Proof of Concept

Docker Image Size Docker Pulls Docker Stars GitHub license

Critical Security Vulnerability Demo - CVSS 10.0 - Remote Code Execution in React Server Components

⚠️DISCLAIMER

FOR EDUCATIONAL PURPOSES ONLY!
This repository demonstrates a critical security vulnerability.
Never use on production systems or exposed networks.

🚨Vulnerability Details

  • CVE-2025-55182 (React) / CVE-2025-66478 (Next.js)
CVE ID:
  • CVSS Score: 10.0 (CRITICAL)
  • Affected: Next.js 15.0.0 with React Server Components
  • Vulnerability: Remote Code Execution via RSC protocol
  • Fixed in: [email protected], [email protected], [email protected]
  • 🐳 Docker Hub

    https://hub.docker.com/r/ihsansencan/react2shell

    root@kitploit:~
    # Pull and run directly
    docker run -p 3000:3000 ihsansencan/react2shell:latest
    
    # CVE
    docker run -p 3000:3000 ihsansencan/react2shell:cve-2025-55182
    docker run -p 3000:3000 ihsansencan/react2shell:cve-2025-66478
    
    # Versioned
    docker run -p 3000:3000 ihsansencan/react2shell:v1.0
    
    

    🛠️Quick Start

    root@kitploit:~
    # 1. Build the vulnerable container
    docker build -t cve-2025-55182-poc .
    
    # 2. Run the demo
    docker run -p 3000:3000 --name react2shell cve-2025-55182-poc
    
    # 3. Open browser
    # http://localhost:3000
    

    🔧 Features

    • Modern UI pretending to be a "code playground"
    • Interactive RCE interface
    • Multiple payload examples
    • Real-time execution results
    • Educational exploit demonstration

    🛡️ Security Impact

    The vulnerability allows:

    • Remote command execution as root
    • Filesystem access
    • Network reconnaissance
    • Potential container escape
    • Full system compromise

    📁 Project Structure

    root@kitploit:~
    /react2shell
    ├── Dockerfile
    ├── package.json
    ├── next.config.js
    ├── app/
    │   ├── actions.js
    │   ├── layout.js
    │   ├── page.js
    │   └── api/
    │       └── command/
    │           └── route.js
    ├── README.md
    ├── LICENSE
    └── img/
        ├── 1.png
        ├── 2.png
        └── 3.png
    

    🚀 Demo Screenshot

    alt text alt text alt text

    🔒 Patching

    root@kitploit:~
    # IMMEDIATE FIX
    npm install [email protected] [email protected] [email protected]
    

    Happy Coding! 💻

    Made with ❤️ by Ihsan Sencan

    ⭐ Star this repo if you find it useful! ⭐

    GitHub followers GitHub stars

    Download Tool