Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
study-CVE-2025-55182 — Educational repository for learning CVE-2025-55182: a pre-authentication RCE in React Server Components. Includes step-by-step documentation, hands-on exercises, and a proof-of-concept exploit in a vulnerable Dockerized Next.js app. | Kitploit
Tools/GitHubGitHub/itumo-arigatone/study-cve-2025-55182
Vulnerability AnalysisExploitationWeb Application ExploitationLearning & EducationPayload DevelopmentLabs & Practice
GitHubitumo-arigatone/study-cve-2025-55182

study-CVE-2025-55182

Educational repository for learning CVE-2025-55182: a pre-authentication RCE in React Server Components. Includes step-by-step documentation, hands-on exercises, and a proof-of-concept exploit in a vulnerable Dockerized Next.js app.

View Repository
138 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182 Study

A repository for learning about the Remote Code Execution (RCE) vulnerability in React Server Components.

🔴 Warning

For educational purposes only. Using it against others' systems without permission is illegal.

📋 Vulnerability Overview

ItemDescription
CVE IDCVE-2025-55182
TypePre-authentication Remote Code Execution (RCE)
CWECWE-502: Deserialization of Untrusted Data
CVSS10.0 (Critical)
AffectedReact 19.0.0 - 19.2.2

📁 Repository Structure

.
├── docs/                    # 📚 学習ドキュメント(Step 1-4)
├── exercises/               # 🧪 演習スクリプト
├── exploit/                 # 💀 PoC スクリプト
└── vulnerable-app/          # 🎯 脆弱なNext.jsアプリ

🚀 Quick Start

1. Start the vulnerable app

cd vulnerable-app
docker compose up --build -d

2. Run the exploit

cd exploit
pip install -r requirements.txt
python3 poc.py http://localhost:3000 "id"

3. Check the result

uid=0(root) gid=0(root) groups=0(root)...

🎉 RCE Success!

📚 Learning Flow

Documents to understand the vulnerability step by step:

StepTopicFile
1Prototype Pollution Basicsdocs/01_prototype_pollution_basics.md
2Constructor Chain and RCEdocs/02_constructor_chain.md
3React Flight Protocoldocs/03_react_flight_protocol.md
4Vulnerability Overview and Fixdocs/04_vulnerability_summary.md

🧪 Run Exercises

# Step 1: Experience Prototype Pollution
node exercises/01_prototype_pollution.js

# Step 2: Understand Constructor Chain
node exercises/02_constructor_chain.js

# Step 3: Simulate reference resolution
node exercises/03_reference_resolution.js

# Step 4: Full exploit analysis
node exercises/04_full_exploit_analysis.js

🛡️ How to Fix

# Update React to the latest version
npm install react@latest react-dom@latest

Fixed versions: 19.0.3+, 19.1.4+, 19.2.3+

📚 References

  • CVE-2025-55182
  • GitHub PR #35277 - Fix patch
  • React Security Advisory
Download Tool