Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
react2shell-scanner — Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives. | Kitploit
Tools/GitHubGitHub/nxgn-kd01/react2shell-scanner
Vulnerability ScannersCode AnalysisExploitationWeb Application ExploitationDevSecOpsSupply Chain Security
GitHubnxgn-kd01/react2shell-scanner

react2shell-scanner

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.

View Repository
3109 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 React2Shell Scanner

CVSS 10.0 RCE in React Server Components. Is your React 19 app vulnerable?

Fast, accurate scanner for CVE-2025-55182 (React2Shell) - a critical remote code execution vulnerability exploited in the wild. Zero false positives with intelligent Server Components detection.

CVSS Score License: MIT GitHub Issues GitHub Stars PRs Welcome

🚨 About React2Shell (CVE-2025-55182)

React2Shell is a maximum severity (10.0 CVSS) vulnerability in React Server Components that allows unauthenticated remote code execution. Attackers can exploit this through specially crafted HTTP requests to Server Function endpoints.

Key Facts:

  • Affected: React 19.x, Next.js 14-16.x, react-router, waku, @parcel/rsc, expo
  • Attack Vector: Network (no authentication required)
  • Impact: Complete server compromise (RCE)
  • Disclosure: December 3, 2025
  • Exploitation: Near 100% success rate in default configurations
  • Related CVEs: CVE-2025-55184 (DoS), CVE-2025-55183 (Source Exposure), CVE-2025-67779

⚠️ Critical Note: Only React 19.x is vulnerable. React 18.x and earlier are NOT affected.

⚡ Quick Start (30 seconds)

# Option A: Node.js scanner (recommended - cross-platform, no dependencies)
npx react2shell-scanner /path/to/your/project

# Option B: Direct download and run
curl -sSL https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js > scan.js
node scan.js /path/to/your/project

# Option C: Clone and run
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
node scan.js /path/to/your/project

Results in seconds: 🚨 Vulnerable | ⚠️ Warnings | ✅ Safe

📋 What This Scanner Checks

This tool performs intelligent vulnerability detection:

1. React Version Analysis 🔴 Critical

  • Detects vulnerable React 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • Confirms React 18.x apps are safe (prevents false positives)
  • Identifies react-server-dom-* packages

2. Framework Configuration Check 🟡 Warning

  • Scans Next.js 14.x-canary through 16.x versions
  • Detects react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, rwsdk, expo
  • Validates React 19 dependency where required
  • Detects static export mode (Server Components disabled = safe)

3. Server Function Detection 🔍 Deep Analysis

  • Scans source files for 'use server' directives
  • Identifies files containing Server Functions
  • Only flags projects that actually use Server Components
  • Note: Dynamically imported Server Functions require manual review

4. Smart False Positive Prevention ✅ Accuracy

  • Only flags apps with React 19 + Server Components + 'use server' directives
  • Provides context for edge cases
  • Explains why projects are/aren't vulnerable

5. Multi-Project Scanning 📁 Scale

  • Recursive directory scanning
  • Detects npm, yarn, and pnpm projects
  • Generates project-specific fix commands

🎯 Scanner Features

PropertyValue
CVE IDCVE-2025-55182
NameReact2Shell
CVSS Score10.0 (CRITICAL)
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack VectorNetwork
AuthenticationNone required
ImpactComplete system compromise

Affected Versions

React:

  • 19.0.0, 19.1.0, 19.1.1, 19.2.0

React Server DOM Packages:

  • react-server-dom-webpack 19.0.0 - 19.2.0
  • react-server-dom-parcel 19.0.0 - 19.2.0
  • react-server-dom-turbopack 19.0.0 - 19.2.0

Next.js:

  • 14.0.0 to 14.2.34
  • 14.3.0-canary.0 to 14.3.0-canary.87
  • 15.0.0 to 15.0.6
  • 15.1.0 to 15.1.8
  • 15.2.0 to 15.2.5
  • 15.3.0 to 15.3.5
  • 15.4.0 to 15.4.7
  • 15.5.0 to 15.5.6
  • 16.0.0 to 16.0.9

Additional Affected Frameworks (per React official advisory):

  • react-router 7.0.0 - 7.1.3
  • waku 0.21.0 - 0.21.5
  • @parcel/rsc 2.12.0 - 2.13.2
  • @vitejs/plugin-rsc 0.1.0 - 0.2.0
  • rwsdk (Redwood SDK) 0.1.0 - 0.4.0
  • expo 52.0.0 - 52.0.9

Patched Versions

React: 19.2.1 or later

Next.js:

  • 14.2.35+, 14.3.0-canary.88+
  • 15.0.7+, 15.1.9+, 15.2.6+, 15.3.6+, 15.4.8+, 15.5.7+
  • 16.0.10+

Other Frameworks:

  • react-router: 7.1.4+
  • waku: 0.21.6+
  • @parcel/rsc: 2.13.3+
  • @vitejs/plugin-rsc: 0.2.1+
  • rwsdk: 0.4.1+
  • expo: 52.0.10+

🚀 Getting Started

Prerequisites

Node.js Scanner (Recommended):

  • Node.js 12+ (cross-platform, no dependencies)

Bash Scanner:

  • Bash 3.2+ (macOS/Linux)
  • jq (JSON processor)
# Install jq (if using Bash scanner)
# macOS
brew install jq

# Ubuntu/Debian
sudo apt-get install jq

# RHEL/CentOS
sudo yum install jq

Step 1: Get the Scanner

Option A: Clone (Recommended for users)

# Clone the repository
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner

# Make scripts executable
chmod +x scan.sh scan.js

Option B: Fork (Recommended for contributors)

# Fork on GitHub (click "Fork" button on repository page)
# Then clone your fork
git clone https://github.com/YOUR_USERNAME/react2shell-scanner.git
cd react2shell-scanner

# Make scripts executable
chmod +x scan.sh scan.js

# Add upstream remote to stay updated
git remote add upstream https://github.com/nxgn-kd01/react2shell-scanner.git

Option C: Direct Download

# Node.js version (recommended - cross-platform)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js
chmod +x scan.js

# Bash version (Unix/Linux/macOS only)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.sh
chmod +x scan.sh

💻 Usage

Step 2: Run the Scanner

🔍 Scan current directory:

# Using Node.js (recommended)
node scan.js

# Using Bash
./scan.sh

📁 Scan specific project:

node scan.js /path/to/project
./scan.sh /path/to/project

🗂️ Recursive scan (all subdirectories):

node scan.js -r
./scan.sh -r

Advanced Options

JSON output (for automation):

node scan.js --json
./scan.sh --json

CI/CD mode (exits with code 1 if vulnerable):

node scan.js --ci
./scan.sh --ci

Verbose output:

node scan.js -v
./scan.sh -v

Combine options:

node scan.js /path/to/projects -r --json --ci
./scan.sh /path/to/projects -r --json --ci

Command Line Options

OptionDescription
-r, --recursiveScan all subdirectories for Node.js projects
-v, --verboseShow detailed output
--jsonOutput results as JSON
--ciExit with code 1 if vulnerabilities found (for CI/CD)
-h, --helpShow help message

Exit Codes

CodeMeaning
0No vulnerabilities found
1Vulnerabilities found (when using --ci flag)
2Scan error occurred

Examples

Example 1: Scan a single project

$ node scan.js ~/my-react-app

╔════════════════════════════════════════════════════════════╗
║  CVE-2025-55182 Scanner (React2Shell)                      ║
╚════════════════════════════════════════════════════════════╝

Severity: CRITICAL (CVSS 10.0)
Description: Unauthenticated RCE in React Server Components

Scan Summary:
  Total projects: 1
  Vulnerable: 1
  Safe: 0
Download Tool