Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
react2shell-CVE-2025-55182-poc — Python PoC for CVE-2025-55182 (React2Shell) RCE in Next.js/React Server Components with dynamic WAF bypass padding for authorized security testing. | Kitploit
Tools/GitHubGitHub/joelvaiju/react2shell-cve-2025-55182-poc
Vulnerability AnalysisExploitationWeb Application ExploitationWAF BypassPenetration TestingPayload Development
GitHubjoelvaiju/react2shell-cve-2025-55182-poc

react2shell-CVE-2025-55182-poc

Python PoC for CVE-2025-55182 (React2Shell) RCE in Next.js/React Server Components with dynamic WAF bypass padding for authorized security testing.

View Repository
3189 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182 (React2Shell) PoC with WAF Bypass

A clean, reliable Python proof-of-concept exploit for CVE-2025-55182 (aka React2Shell), a critical remote code execution vulnerability in React Server Components used by Next.js (App Router) and similar frameworks.

This PoC includes dynamic WAF bypass padding to evade common web application firewalls (Cloudflare, AWS WAF, etc.) that limit deep inspection of large multipart bodies.

Vulnerability Overview

  • CVE: CVE-2025-55182
  • CVSS: 10.0 (Critical)
  • Affected: Next.js 15.x–16.0.6, React 19.0.0–19.2.0 (with Server Components enabled)
  • Impact: Unauthenticated arbitrary command execution on the server

Requirements

  • Python 3.6+
  • requests library
pip install requests

Usage

Basic RCE

python poc.py https://vulnerable-target.com "id"

With WAF bypass (256 KB padding)

python poc.py https://vulnerable-target.com "whoami" 256

Arguments

  • url: Target URL (root / or /formaction commonly works)
  • command: Command to execute on the server
  • padding_kb (optional): Size of junk padding in KB (default: 128). Increase if blocked by WAF.

Example Output

[*] Sending payload to https://vulnerable-target.com with 256KB padding...
[*] Command: id
[+] RCE Successful! Output:

uid=1000(node) gid=1000(node) groups=1000(node),4(adm),27(sudo)

Responsible Disclosure

This tool is for authorized security testing and research only.

  • Use only on targets you own or have explicit permission to test.
  • Do not use against production systems without authorization.
  • Report findings responsibly through bug bounty programs or direct vendor contact.

Mitigation

  • Upgrade to Next.js ≥ 16.0.7 or React ≥ 19.2.1
  • Deploy updated WAF rules (e.g., AWS KnownBadInputsRuleSet v1.24+, Cloudflare managed rulesets)
  • Disable unused Server Actions / RSC endpoints

References

  • CVE Details: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55182
  • Original Advisory: (React/Next.js security bulletin)
  • Related PoCs: https://github.com/msanft/CVE-2025-55182
Download Tool