Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PunchingBag-for-React2Shell β€” Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges | Kitploit
Tools/GitHubGitHub/machine-farmer/punchingbag-for-react2shell
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingLearning & EducationRed TeamingRemote Access ToolLabs & Practice
GitHubmachine-farmer/punchingbag-for-react2shell

PunchingBag-for-React2Shell

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

View Repository
1189 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

πŸ₯Š PunchingBag - CVE-2025-55182 Security Research Platform

Next.js React Docker License CVE PunchingBag Platform

⚠️ EDUCATIONAL PURPOSE ONLY: This is an intentionally vulnerable application designed for authorized security research and CTF challenges. Do NOT use these techniques on unauthorized systems.

A deliberately vulnerable Next.js 15.1.6 application that demonstrates CVE-2025-55182 (React2Shell) - a critical Remote Code Execution vulnerability in React Server Components. Built for security researchers, penetration testers, and students to practice exploitation techniques in a safe, isolated environment.


πŸ“‹ Table of Contents

  • About CVE-2025-55182
  • Features
  • Prerequisites
  • Installation
  • Usage
  • CTF Challenges
  • Exploitation Guide
  • Project Structure
  • Security Notice
  • Contributing
  • License
  • Acknowledgments

πŸ” About CVE-2025-55182

CVE-2025-55182, also known as React2Shell, is a critical Remote Code Execution (RCE) vulnerability affecting React Server Components in Next.js.

Vulnerability Details

  • CVE ID: CVE-2025-55182
  • Type: Remote Code Execution (RCE)
  • CVSS Score: 10.0 (Critical)
  • Affected Versions: Next.js 15.1.6 and earlier with React Server Components enabled
  • Attack Vector: Unsafe deserialization in RSC Flight protocol
  • Impact: Complete system compromise, data exfiltration, privilege escalation

How It Works

The vulnerability stems from improper handling of serialized data in React Server Actions. Attackers can craft malicious payloads that bypass validation and execute arbitrary code on the server through:

  1. Prototype pollution in JavaScript objects
  2. Unsafe deserialization of React Flight payloads
  3. Server Action parameter manipulation
  4. Header injection in Server Components

✨ Features

  • 🐳 Fully Dockerized - Complete isolation from host system
  • 🎯 5 CTF Flags - Progressive difficulty challenges
  • πŸ”“ Multiple Attack Vectors - Server Actions, API routes, authentication bypass
  • πŸ“š Educational Resources - Built-in hints and exploitation guides
  • πŸ›‘οΈ Safe Environment - No risk to production systems
  • 🎨 Realistic Application - Realistic app theme with admin panel
  • πŸ“Š Progress Tracking - Monitor your flag captures
  • πŸ”§ Vulnerable Version of React and Next.js - React 19.0.0, Next.js 15.1.6

πŸ”§ Prerequisites

Before you begin, ensure you have the following installed:

  • Docker: Version 20.10 or higher
  • Docker Compose: Version 2.0 or higher
  • Git: For cloning the repository

Check Your Installation

docker --version
docker-compose --version
git --version

πŸ“¦ Installation

Quick Start

# 1. Clone the repository
git clone https://github.com/Machine-farmer/PunchingBag-for-React2Shell.git
cd PunchingBag-for-React2Shell

# 2. Build and run with Docker
docker-compose up --build

# 3. Access the application
# Open your browser to: http://localhost:3000

Manual Setup (Without Docker)

# 1. Clone the repository
git clone https://github.com/Machine-farmer/punchingbag-cve-2025-55182.git
cd punchingbag-cve-2025-55182

# 2. Install dependencies
npm install

# 3. Run development server
npm run dev

# 4. Access at http://localhost:3000

⚠️ Warning: Manual setup without Docker is NOT recommended for security research. Always use Docker for isolation.


πŸš€ Usage

Starting the Environment

# Start the vulnerable application
docker-compose up

# Start in detached mode (background)
docker-compose up -d

# View logs
docker-compose logs -f

Stopping the Environment

# Stop containers
docker-compose down

# Stop and remove volumes
docker-compose down -v

# Complete cleanup (removes images)
docker-compose down -v --rmi all

Accessing the Application

Once running, navigate to:

  • Homepage: http://localhost:3000
  • Dashboard: http://localhost:3000/dashboard
  • Admin Panel: http://localhost:3000/admin

🎯 CTF Challenges

PunchingBag contains 5 hidden flags that test different exploitation techniques:

FlagChallengeDifficultyPoints
🚩 Flag 1Basic ReconnaissanceEasy100
🚩 Flag 2Server Action ExploitMedium200
🚩 Flag 3Admin Access BypassMedium300
🚩 Flag 4Remote Code ExecutionHard400
🚩 Flag 5Environment SecretsMedium250

Flag Format

All flags follow the format: CTF{description_here}

Hints

  • Flag 1: Explore the application structure and dashboard
  • Flag 2: Look for Server Actions that accept user input
  • Flag 3: Check environment variables for credentials
  • Flag 4: Exploit the RCE vulnerability in admin console
  • Flag 5: Extract hidden configuration data

πŸ”“ Exploitation Guide

Tools You'll Need

  • Burp Suite - HTTP request interception and modification
  • curl - Command-line HTTP client for payload crafting
  • Browser DevTools - Network traffic inspection
  • Postman - API testing (optional)

Basic Exploitation Workflow

1. Reconnaissance

# Explore the application
curl http://localhost:3000

# Check available endpoints
curl http://localhost:3000/dashboard
curl http://localhost:3000/admin

2. Server Action Exploitation

Intercept form submissions and modify the payload:

// Example malicious payload
{
  "name": "attacker",
  "email": "[email protected]",
  "message": "__proto__: { isAdmin: true }"
}

3. Header Injection

# Inject malicious headers
curl -X POST http://localhost:3000/api/data \
  -H "Content-Type: application/json" \
  -H "x-user-data: {\"role\":\"admin\"}" \
  -d '{"exploit": true}'

4. Admin Access

Check .env.local for credentials or exploit the authentication:

# Default admin token (intentionally weak)
Username: admin
Token: super_secret_admin_key_12345

5. Remote Code Execution

On vulnerable component use the command execution feature:

# Simulate RCE
Command: cat /flag.txt

Advanced Techniques

  • Prototype Pollution: Inject __proto__ properties
  • RSC Payload Crafting: Modify React Flight serialized data
  • Session Hijacking: Manipulate authentication tokens
  • API Fuzzing: Test all endpoints for vulnerabilities

πŸ“ Project Structure

Download Tool