Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/logesh-git001/cve-2025-55182
Vulnerability AnalysisExploitationWeb Application ExploitationThreat IntelligenceLearning & EducationIncident Response
GitHublogesh-git001/cve-2025-55182

CVE-2025-55182

"One crafted HTTP request can compromise your entire server." — React Security Team, Dec 2025

View Repository
2105 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182 — React2Shell

Critical Remote Code Execution in React Server Components.

Severity: CRITICAL | CVSS v3.1: 10.0 (Maximum) | Status: Actively Exploited


What Is This?

React2Shell is a critical security vulnerability in React Server Components (RSC) — a modern feature that lets React run parts of your web app on the server instead of the browser.

The flaw allows any attacker on the internet — with no login, no special access, and no prior knowledge of your system — to send a single malicious HTTP request to your server and run any code they want on it. That means they can steal data, install malware, lock your files with ransomware, or take full control of your server.

Think of it like this: your server has a door that was supposed to only open for trusted visitors, but it turns out anyone can walk in — just by knocking in a specific way.


Quick Reference

PropertyValue
CVE IDCVE-2025-55182 (also called React2Shell)
SeverityCritical — Remote Code Execution (RCE)
CVSS v3.1 Score10.0 / 10.0 (maximum possible)
CVSS v4 Score9.3 / 10.0
Weakness TypeCWE-502 — Deserialization of Untrusted Data
Attack MethodSingle HTTP POST request, no authentication needed
Discovered ByLachlan Davidson (security researcher)
DisclosedDecember 3, 2025
Exploit StatusPublic exploit available — actively used by attackers
Related CVECVE-2025-66478 (Next.js — confirmed duplicate)

Who Is Affected?

Vulnerable React Versions

react-server-dom-webpack   — versions 19.0.0, 19.1.0, 19.1.1, 19.2.0
react-server-dom-parcel    — versions 19.0.0, 19.1.0, 19.1.1, 19.2.0
react-server-dom-turbopack — versions 19.0.0, 19.1.0, 19.1.1, 19.2.0

Affected Frameworks

Framework / ToolAffected Scope
Next.js 15.x – 16.xApp Router only — Pages Router is NOT affected
React Router RSCUnstable / preview channel only
Redwood SDKRSC mode only
WakuAll versions with RSC enabled
ExpoRSC preview builds only
Vite RSC PluginAll integrations
Parcel RSC PluginAll integrations
Any custom RSC setupAny server using RSC Flight deserialization

⚠️ Important: You are vulnerable even if you do not use Server Actions or Server Functions explicitly — as long as React Server Components are enabled in your app.

✅ Not affected: Apps using only the Pages Router, or apps with no server-side React at all.


Why Is This So Dangerous?

Three reasons make React2Shell exceptionally severe:

  1. No authentication required. Anyone on the internet can attempt this attack. No account, no token, no prior access needed.

  2. Works on default installations. A brand-new Next.js app created with create-next-app — with zero custom configuration — is immediately exploitable. Developers do not have to do anything wrong to be vulnerable.

  3. Near-100% reliability. Security researchers confirmed the exploit works almost every time against unpatched servers.


How Does the Attack Work?

The Root Cause — In Plain English

When your React server receives data from a client, it processes (deserializes) that data to understand what to do next. The problem is that React never checks whether that data is safe or legitimate — it blindly trusts whatever arrives.

An attacker exploits this by sending specially crafted data that hijacks internal JavaScript behavior on the server, ultimately allowing them to inject and execute their own code.

Technical Explanation

The exploit uses a technique called prototype pollution:

  1. The attacker sends a crafted HTTP POST request to any RSC endpoint (no special URL needed).
  2. The React Flight Protocol parser processes the payload without any structural validation.
  3. The malicious payload pollutes Object.prototype.then — a fundamental JavaScript object that all other objects inherit from.
  4. This grants the attacker access to JavaScript's Function constructor.
  5. The attacker uses the Function constructor to execute arbitrary code as the Node.js server process.
Step 1 — Attacker sends crafted HTTP POST
         ↓
Step 2 — React deserializes payload blindly
         ↓
Step 3 — Object.prototype.then is hijacked (prototype pollution)
         ↓
Step 4 — Function constructor is accessed
         ↓
Step 5 — Attacker's code runs on the server
         ↓
Step 6 — Attacker has full server control

Simplified Code Illustration

// This is a simplified version of the vulnerable code path inside React
function parseFlightRequest(req) {
    const flight = req.body;

    // ❌ NO validation — the server trusts whatever arrives
    const decoded = dangerousDeserialize(flight);  // Attack happens here

    // If the attacker controls decoded.action → RCE
    return executeServerReference(decoded.action);
}

What the Attack Looks Like

POST /?flight=1 HTTP/1.1
Content-Type: text/plain

{
  "status": "resolved_model",
  "$1:__proto__:then": "node:process.mainModule.require('child_process').execSync('id > /tmp/rce')",
  "_formData.get": "$1:constructor:constructor"
}
# Simplified cURL version of the exploit
curl -X POST https://target.com/react?flight=1 \
  -H "Content-Type: text/plain" \
  --data '["$ACTION_REF","__proto__","constructor","<attacker_payload>"]'

🚫 Legal warning: Do not use this against any system you do not own or have explicit written authorization to test.


Fixed Versions — Patch Now

React RSC Packages

PackagePatched Version
react-server-dom-webpack19.0.1, 19.1.2, 19.2.1+
react-server-dom-parcel19.0.1, 19.1.2, 19.2.1+
react-server-dom-turbopack19.0.1, 19.1.2, 19.2.1+

💡 Recommendation: Upgrade to 19.2.3 to also fix related follow-on vulnerabilities (CVE-2025-55183, CVE-2025-55184, CVE-2025-67779).

Next.js

Your VersionUpgrade To
13.x / 14.x14.2.35
15.0.x15.0.5
15.1.x15.1.9
15.2.x15.2.6
15.3.x15.3.6
15.4.x15.4.8
15.5.x15.5.7
16.0.x16.0.7

How to Protect Yourself — Step by Step

Follow these steps in order. Step 1 and 2 are mandatory. The rest add extra layers of defense.

Step 1 — Upgrade React packages (most important)

# Check your current version
npm list react-server-dom-webpack

# Upgrade to the latest patched version
npm install react-server-dom-webpack@latest
npm install react-server-dom-parcel@latest
npm install react-server-dom-turbopack@latest

Step 2 — Upgrade your framework

# For Next.js — replace X with your patched version from the table above
npm install next@X

Step 3 — Add WAF protection (defense in depth)

Download Tool