
Educational lab demonstrating CVE-2025-55182: Critical RCE in React Server Components via prototype pollution in the Flight protocol
Educational lab demonstrating CVE-2025-55182 — a critical (CVSS 10.0) Remote Code Execution vulnerability in React Server Components caused by prototype pollution in the Flight protocol deserializer.
Disclaimer: This repository is for educational and authorized security research purposes only. Unauthorized access to computer systems is illegal. The author assumes no liability for misuse of this material. Only use against systems you own or have explicit written permission to test. By using this code, you agree that you are responsible for your own actions.
# 1. Clone
git clone https://github.com/Jeanback1/react-rsc-cve-2025-55182-lab.git
cd react-rsc-cve-2025-55182-lab
# 2. Start the lab (vulnerable + patched instances)
docker compose up -d
# Wait ~2 minutes for both containers to build and start.
# 3. Exploit the vulnerable instance
python exploit/exploit.py http://localhost:3011 id
# 4. Try the same against the patched instance — it fails
python exploit/exploit.py http://localhost:3012 id
docker compose
┌────────────────────────────────┐
│ │
attacker ────▶│ :3011 → rsc-lab-vulnerable │ React 19.2.0
│ (Server Action) │ ← exploitable
│ │
│ :3012 → rsc-lab-patched │ React 19.2.1
│ (no Server Action) │ ← patched
└────────────────────────────────┘
| Container | Port | React Version | Server Action | Vulnerable? |
|---|---|---|---|---|
rsc-lab-vulnerable | 3011 | 19.2.0 | Yes | Yes |
rsc-lab-patched | 3012 | 19.2.1 | No | No |
requests (pip install requests)├── docker-compose.yml # Lab orchestration
├── README.md # This file
├── LICENSE
│
├── vulnerable/ # Vulnerable Next.js app
│ ├── Dockerfile
│ ├── package.json # [email protected], [email protected]
│ └── app/
│ ├── layout.tsx
│ ├── page.tsx # Server Component + Server Action
│ └── actions.ts # 'use server' — the attack surface
│
├── patched/ # Patched Next.js app
│ ├── Dockerfile
│ ├── package.json # [email protected], [email protected]
│ └── app/
│ ├── layout.tsx
│ └── page.tsx # Server Component only (no Server Actions)
│
├── exploit/
│ ├── exploit.py # Educational RCE exploit (well-commented)
│ ├── requirements.txt
│ └── pyproject.toml
│
└── docs/
└── CVE-2025-55182.md # Full technical analysis
# Single command execution
python exploit/exploit.py <target> <command>
# Examples
python exploit/exploit.py http://localhost:3011 id
python exploit/exploit.py http://localhost:3011 "cat /etc/passwd"
python exploit/exploit.py http://localhost:3011 "ls -la /app"
The exploit works in three stages:
__proto__ traversal → pollute Object.prototype.thenmultipart/form-data via the Server Action endpointX-Action-Redirect response header (base64-encoded)| Package | Vulnerable | Patched |
|---|---|---|
react | ≤ 19.2.0 | ≥ 19.2.1 |
react-dom | ≤ 19.2.0 | ≥ 19.2.1 |
react-server-dom-webpack | ≤ 19.2.0 | ≥ 19.2.1 |
See docs/CVE-2025-55182.md for a full walkthrough:
__proto__ traversal is dangerous