
CVE-2025-55183 Scanner
A security scanner for detecting CVE-2025-55183 - Next.js React Server Components (RSC) source code disclosure vulnerability.
This scanner detects source code disclosure in Next.js React Server Components (RSC). A malicious HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function when the argument is stringified.
pip install -r requirements.txt
Or install manually:
pip install requests urllib3 tqdm
# Scan a single URL
python3 scanner.py https://example.com
# Scan from a file with host list
python3 scanner.py hosts.txt
Create a text file with one host per line. The scanner will extract the hostname from the first column (supports tab or space-separated input):
example.com 192.0.2.1 Cloudflare
subdomain.example.com 192.0.2.2 Cloudflare
https://app.example.com
Lines starting with # are treated as comments and ignored.
positional arguments:
input Target URL or file containing list of hosts
optional arguments:
-h, --help Show help message and exit
-t TIMEOUT, --timeout TIMEOUT
Request timeout in seconds (default: 10)
-o OUTPUT, --output OUTPUT
Output file for results
--format {text,json,csv}
Output format (default: text)
--threads THREADS Number of concurrent threads (default: 1)
--delay DELAY Delay between requests in seconds (default: 0.5)
--rate-limit RATE_LIMIT
Requests per second per host (0 to disable, default: 10.0)
--retries RETRIES Number of retries for failed requests (default: 3)
-v, --verbose Increase verbosity (-v, -vv, -vvv)
-q, --quiet Suppress non-essential output
# Scan with 10 concurrent threads
python3 scanner.py hosts.txt --threads 10
# Output results in JSON format
python3 scanner.py hosts.txt --format json -o results.json
# Output results in CSV format
python3 scanner.py hosts.txt --format csv -o results.csv
# Set delay between requests and rate limit
python3 scanner.py hosts.txt --delay 1.0 --rate-limit 5.0
# Enable verbose output for debugging
python3 scanner.py hosts.txt -vv
# Suppress non-essential output
python3 scanner.py hosts.txt --quiet -o results.json
Human-readable text output with scan summary and detailed results:
============================================================
SCAN SUMMARY
============================================================
Total hosts scanned: 5
Vulnerable hosts: 2
Safe hosts: 3
============================================================
[!] https://example.com - VULNERABLE
Found 3 leaked source code(s)
[+] https://example2.com - Not vulnerable
Structured JSON output with full scan details:
{
"summary": {
"total_hosts": 5,
"vulnerable_hosts": 2,
"safe_hosts": 3
},
"results": [
{
"url": "https://example.com",
"vulnerable": true,
"chunk_paths": ["/_next/static/chunks/..."],
"action_ids": ["abc123..."],
"leaked_sources": [...]
}
]
}
Comma-separated values for easy import into spreadsheets:
URL,Vulnerable,Chunks Found,Action IDs Found,Leaked Sources Count,Error
https://example.com,Yes,5,3,2,
https://example2.com,No,0,0,0,
The scanner performs a three-step process:
/_next/static/chunks/ references$F1 payload to each action ID to trigger source code disclosure0: No vulnerable hosts found1: One or more vulnerable hosts foundIf you encounter connection errors:
--timeout 30-vv to see detailed error messagesIf targets are blocking requests:
--delay 2.0--rate-limit 2.0--threads 1If you see import errors:
pip install -r requirements.txt
Note: tqdm is optional - the scanner will work without it but won't show progress bars.
This tool is provided for educational and authorized security testing purposes only.
This tool is designed for security research and authorized penetration testing. Unauthorized use against systems you don't own or have permission to test is illegal and unethical. The authors are not responsible for any misuse of this tool.