
Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.
CVSS 10.0 RCE in React Server Components. Is your React 19 app vulnerable?
Fast, accurate scanner for CVE-2025-55182 (React2Shell) - a critical remote code execution vulnerability exploited in the wild. Zero false positives with intelligent Server Components detection.
React2Shell is a maximum severity (10.0 CVSS) vulnerability in React Server Components that allows unauthenticated remote code execution. Attackers can exploit this through specially crafted HTTP requests to Server Function endpoints.
Key Facts:
⚠️ Critical Note: Only React 19.x is vulnerable. React 18.x and earlier are NOT affected.
# Option A: Node.js scanner (recommended - cross-platform, no dependencies)
npx react2shell-scanner /path/to/your/project
# Option B: Direct download and run
curl -sSL https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js > scan.js
node scan.js /path/to/your/project
# Option C: Clone and run
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
node scan.js /path/to/your/project
Results in seconds: 🚨 Vulnerable | ⚠️ Warnings | ✅ Safe
This tool performs intelligent vulnerability detection:
'use server' directivesReact:
19.0.0, 19.1.0, 19.1.1, 19.2.0React Server DOM Packages:
react-server-dom-webpack 19.0.0 - 19.2.0react-server-dom-parcel 19.0.0 - 19.2.0react-server-dom-turbopack 19.0.0 - 19.2.0Next.js:
14.0.0 to 14.2.3414.3.0-canary.0 to 14.3.0-canary.8715.0.0 to 15.0.615.1.0 to 15.1.815.2.0 to 15.2.515.3.0 to 15.3.515.4.0 to 15.4.715.5.0 to Additional Affected Frameworks (per React official advisory):
react-router 7.0.0 - 7.1.3waku 0.21.0 - 0.21.5@parcel/rsc 2.12.0 - 2.13.2@vitejs/plugin-rsc 0.1.0 - 0.2.0rwsdk (Redwood SDK) 0.1.0 - 0.4.0expo 52.0.0 - 52.0.9React: 19.2.1 or later
Next.js:
14.2.35+, 14.3.0-canary.88+15.0.7+, 15.1.9+, 15.2.6+, 15.3.6+, 15.4.8+, 15.5.7+16.0.10+Other Frameworks:
react-router: 7.1.4+waku: 0.21.6+@parcel/rsc: 2.13.3+@vitejs/plugin-rsc: 0.2.1+rwsdk: 0.4.1+expo: 52.0.10+Node.js Scanner (Recommended):
Bash Scanner:
# Install jq (if using Bash scanner)
# macOS
brew install jq
# Ubuntu/Debian
sudo apt-get install jq
# RHEL/CentOS
sudo yum install jq
Option A: Clone (Recommended for users)
# Clone the repository
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
# Make scripts executable
chmod +x scan.sh scan.js
Option B: Fork (Recommended for contributors)
# Fork on GitHub (click "Fork" button on repository page)
# Then clone your fork
git clone https://github.com/YOUR_USERNAME/react2shell-scanner.git
cd react2shell-scanner
# Make scripts executable
chmod +x scan.sh scan.js
# Add upstream remote to stay updated
git remote add upstream https://github.com/nxgn-kd01/react2shell-scanner.git
Option C: Direct Download
# Node.js version (recommended - cross-platform)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js
chmod +x scan.js
# Bash version (Unix/Linux/macOS only)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.sh
chmod +x scan.sh
🔍 Scan current directory:
# Using Node.js (recommended)
node scan.js
# Using Bash
./scan.sh
📁 Scan specific project:
node scan.js /path/to/project
./scan.sh /path/to/project
🗂️ Recursive scan (all subdirectories):
node scan.js -r
./scan.sh -r
JSON output (for automation):
node scan.js --json
./scan.sh --json
CI/CD mode (exits with code 1 if vulnerable):
node scan.js --ci
./scan.sh --ci
Verbose output:
node scan.js -v
./scan.sh -v
Combine options:
node scan.js /path/to/projects -r --json --ci
./scan.sh /path/to/projects -r --json --ci
| Code | Meaning |
|---|---|
| 0 | No vulnerabilities found |
| 1 | Vulnerabilities found (when using --ci flag) |
| 2 | Scan error occurred |
$ node scan.js ~/my-react-app
╔════════════════════════════════════════════════════════════╗
║ CVE-2025-55182 Scanner (React2Shell) ║
╚════════════════════════════════════════════════════════════╝
Severity: CRITICAL (CVSS 10.0)
Description: Unauthenticated RCE in React Server Components
Scan Summary:
Total projects: 1
Vulnerable: 1
Safe: 0
⚠ VULNERABLE PROJECTS FOUND:
1. /Users/user/my-react-app
└─ react 19.0.0 → 19.2.1
└─ next 15.0.3 → 15.0.5
Fix command:
$ cd /Users/user/my-react-app
$ npm install [email protected] [email protected]
$ node scan.js ~/projects -r --json > results.json
{
"vulnerability": "CVE-2025-55182",
"severity": "CRITICAL",
"cvss": 10.0,
"scanned": 5,
"vulnerable": 2,
"results": [
{
"path": "/Users/user/projects/app1",
"vulnerable": true,
"packages": [
{
"name": "react",
"version": "19.0.0",
"fixVersion": "19.2.1"
}
],
"packageManager": "npm",
"fixCommands": [
"cd /Users/user/projects/app1",
"npm install [email protected]"
]
}
]
}
.github/workflows/security-scan.yml
name: CVE-2025-55182 Security Scan
on: [push, pull_request]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Set up Node.js
uses: actions/setup-node@v3
with:
node-version: '18'
- name: Download CVE-2025-55182 Scanner
run: |
curl -O https://raw.githubusercontent.com/nxgn-kd01/cve-2025-55182-scanner/main/scan.js
chmod +x scan.js
- name: Scan for vulnerabilities
run: node scan.js --ci
GitLab CI (.gitlab-ci.yml)
security-scan:
stage: test
image: node:18
script:
- curl -O https://raw.githubusercontent.com/nxgn-kd01/cve-2025-55182-scanner/main/scan.js
- chmod +x scan.js
- node scan.js --ci
allow_failure: false
The scanner performs the following checks:
package.json filesdependencies and devDependencies'use server' directives in source files'use server' directives (indicates Server Functions in use)The scanner includes intelligent detection to prevent false positives:
output: 'export' are marked as likely safe'use server' directives to confirm actual Server Component usageExample Output:
✓ No vulnerable projects found
ℹ Projects with analysis notes:
1. /path/to/project
ℹ Next.js ^15.1.3 is in vulnerable range, but using React 18 (safe - only React 19 affected)
2. /path/to/another-project
ℹ Next.js 16.0.5 with React 19 detected, but no 'use server' directives found (likely safe).
Note: dynamically imported Server Functions require manual review.
node scan.js -r
For each vulnerable project, run the suggested fix command:
cd /path/to/project
npm install [email protected] [email protected] # Example
Or with yarn:
yarn upgrade [email protected] [email protected]
Or with pnpm:
pnpm update [email protected] [email protected]
npm test
npm run build
node scan.js --ci
A: Currently, the scanner checks direct dependencies in package.json. For deep dependency scanning, use npm audit or yarn audit in combination with this tool.
A: No, React 18 is NOT affected ✅
CVE-2025-55182 only affects React 19.x Server Components. The scanner will correctly identify React 18 apps as safe, even if using Next.js 15.x or 16.x versions that are in the vulnerable range.
A: Yes! Use the --ci flag to make the scanner exit with code 1 if vulnerabilities are found, which will fail your pipeline. See CI/CD integration examples above.
A: Temporary mitigations (upgrading is the only definitive fix):
⚠️ Critical: These are temporary measures only. Upgrade to patched versions ASAP.
A: Very accurate with intelligent false positive prevention:
'use server' directives to confirm actual vulnerabilityA: The scanner detects 'use server' directives in your source files. However, dynamically imported Server Functions (loaded at runtime via import()) may not be detected statically. If the scanner reports "no 'use server' directives found" but you use dynamic imports for Server Functions, you should manually review those files. The scanner will include a note reminding you of this.
Contributions are welcome! Please feel free to submit issues or pull requests.
# Test on sample projects
./test-scanner.sh
This scanner now detects all major RSC-enabled frameworks per the React official advisory:
For additional frameworks, please open an issue or submit a PR.
MIT License - see LICENSE file for details
This tool is provided as-is for the community to help identify vulnerable projects. Always verify scanner results and test updates in a safe environment before deploying to production.
If you find this tool helpful, please:
Stay safe and keep your dependencies updated!
| Property | Value |
|---|
| CVE ID | CVE-2025-55182 |
| Name | React2Shell |
| CVSS Score | 10.0 (CRITICAL) |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Attack Vector | Network |
| Authentication | None required |
| Impact | Complete system compromise |
15.5.616.0.0 to 16.0.9| Option | Description |
|---|
-r, --recursive | Scan all subdirectories for Node.js projects |
-v, --verbose | Show detailed output |
--json | Output results as JSON |
--ci | Exit with code 1 if vulnerabilities found (for CI/CD) |
-h, --help | Show help message |