
Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.
CVSS 10.0 RCE in React Server Components. Is your React 19 app vulnerable?
Fast, accurate scanner for CVE-2025-55182 (React2Shell) - a critical remote code execution vulnerability exploited in the wild. Zero false positives with intelligent Server Components detection.
React2Shell is a maximum severity (10.0 CVSS) vulnerability in React Server Components that allows unauthenticated remote code execution. Attackers can exploit this through specially crafted HTTP requests to Server Function endpoints.
Key Facts:
⚠️ Critical Note: Only React 19.x is vulnerable. React 18.x and earlier are NOT affected.
# Option A: Node.js scanner (recommended - cross-platform, no dependencies)
npx react2shell-scanner /path/to/your/project
# Option B: Direct download and run
curl -sSL https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js > scan.js
node scan.js /path/to/your/project
# Option C: Clone and run
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
node scan.js /path/to/your/project
Results in seconds: 🚨 Vulnerable | ⚠️ Warnings | ✅ Safe
This tool performs intelligent vulnerability detection:
'use server' directives| Property | Value |
|---|---|
| CVE ID | CVE-2025-55182 |
| Name | React2Shell |
| CVSS Score | 10.0 (CRITICAL) |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Attack Vector | Network |
| Authentication | None required |
| Impact | Complete system compromise |
React:
19.0.0, 19.1.0, 19.1.1, 19.2.0React Server DOM Packages:
react-server-dom-webpack 19.0.0 - 19.2.0react-server-dom-parcel 19.0.0 - 19.2.0react-server-dom-turbopack 19.0.0 - 19.2.0Next.js:
14.0.0 to 14.2.3414.3.0-canary.0 to 14.3.0-canary.8715.0.0 to 15.0.615.1.0 to 15.1.815.2.0 to 15.2.515.3.0 to 15.3.515.4.0 to 15.4.715.5.0 to 15.5.616.0.0 to 16.0.9Additional Affected Frameworks (per React official advisory):
react-router 7.0.0 - 7.1.3waku 0.21.0 - 0.21.5@parcel/rsc 2.12.0 - 2.13.2@vitejs/plugin-rsc 0.1.0 - 0.2.0rwsdk (Redwood SDK) 0.1.0 - 0.4.0expo 52.0.0 - 52.0.9React: 19.2.1 or later
Next.js:
14.2.35+, 14.3.0-canary.88+15.0.7+, 15.1.9+, 15.2.6+, 15.3.6+, 15.4.8+, 15.5.7+16.0.10+Other Frameworks:
react-router: 7.1.4+waku: 0.21.6+@parcel/rsc: 2.13.3+@vitejs/plugin-rsc: 0.2.1+rwsdk: 0.4.1+expo: 52.0.10+Node.js Scanner (Recommended):
Bash Scanner:
# Install jq (if using Bash scanner)
# macOS
brew install jq
# Ubuntu/Debian
sudo apt-get install jq
# RHEL/CentOS
sudo yum install jq
Option A: Clone (Recommended for users)
# Clone the repository
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
# Make scripts executable
chmod +x scan.sh scan.js
Option B: Fork (Recommended for contributors)
# Fork on GitHub (click "Fork" button on repository page)
# Then clone your fork
git clone https://github.com/YOUR_USERNAME/react2shell-scanner.git
cd react2shell-scanner
# Make scripts executable
chmod +x scan.sh scan.js
# Add upstream remote to stay updated
git remote add upstream https://github.com/nxgn-kd01/react2shell-scanner.git
Option C: Direct Download
# Node.js version (recommended - cross-platform)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js
chmod +x scan.js
# Bash version (Unix/Linux/macOS only)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.sh
chmod +x scan.sh
🔍 Scan current directory:
# Using Node.js (recommended)
node scan.js
# Using Bash
./scan.sh
📁 Scan specific project:
node scan.js /path/to/project
./scan.sh /path/to/project
🗂️ Recursive scan (all subdirectories):
node scan.js -r
./scan.sh -r
JSON output (for automation):
node scan.js --json
./scan.sh --json
CI/CD mode (exits with code 1 if vulnerable):
node scan.js --ci
./scan.sh --ci
Verbose output:
node scan.js -v
./scan.sh -v
Combine options:
node scan.js /path/to/projects -r --json --ci
./scan.sh /path/to/projects -r --json --ci
| Option | Description |
|---|---|
-r, --recursive | Scan all subdirectories for Node.js projects |
-v, --verbose | Show detailed output |
--json | Output results as JSON |
--ci | Exit with code 1 if vulnerabilities found (for CI/CD) |
-h, --help | Show help message |
| Code | Meaning |
|---|---|
| 0 | No vulnerabilities found |
| 1 | Vulnerabilities found (when using --ci flag) |
| 2 | Scan error occurred |
$ node scan.js ~/my-react-app
╔════════════════════════════════════════════════════════════╗
║ CVE-2025-55182 Scanner (React2Shell) ║
╚════════════════════════════════════════════════════════════╝
Severity: CRITICAL (CVSS 10.0)
Description: Unauthenticated RCE in React Server Components
Scan Summary:
Total projects: 1
Vulnerable: 1
Safe: 0