Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
RSC-Scanner-POC — CVE-2025-55183 Scanner | Kitploit
Tools/GitHubGitHub/omaidnebari/rsc-scanner-poc
ReconnaissanceVulnerability ScannersExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubomaidnebari/rsc-scanner-poc

RSC-Scanner-POC

CVE-2025-55183 Scanner

View Repository
969 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Next.js RSC Source Code Disclosure Scanner

A security scanner for detecting CVE-2025-55183 - Next.js React Server Components (RSC) source code disclosure vulnerability.

Description

This scanner detects source code disclosure in Next.js React Server Components (RSC). A malicious HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function when the argument is stringified.

Features

  • 🔍 Automated Scanning: Scans single URLs or bulk host lists
  • ⚡ Concurrent Scanning: Multi-threaded scanning for faster results
  • 🔄 Retry Logic: Automatic retry with exponential backoff for transient failures
  • 📊 Multiple Output Formats: Text, JSON, and CSV output formats
  • 🚦 Rate Limiting: Configurable rate limiting to avoid overwhelming targets
  • 📈 Progress Indicators: Visual progress bars for long scans
  • 🎭 User Agent Rotation: Random user agent rotation to avoid detection
  • 🔇 Verbose Modes: Multiple verbosity levels for debugging

Installation

Prerequisites

  • Python 3.7 or higher

Install Dependencies

pip install -r requirements.txt

Or install manually:

pip install requests urllib3 tqdm

Usage

Basic Usage

# Scan a single URL
python3 scanner.py https://example.com

# Scan from a file with host list
python3 scanner.py hosts.txt

Host List Format

Create a text file with one host per line. The scanner will extract the hostname from the first column (supports tab or space-separated input):

example.com          192.0.2.1        Cloudflare
subdomain.example.com 192.0.2.2        Cloudflare
https://app.example.com

Lines starting with # are treated as comments and ignored.

Command-Line Options

positional arguments:
  input                 Target URL or file containing list of hosts

optional arguments:
  -h, --help           Show help message and exit
  -t TIMEOUT, --timeout TIMEOUT
                       Request timeout in seconds (default: 10)
  -o OUTPUT, --output OUTPUT
                       Output file for results
  --format {text,json,csv}
                       Output format (default: text)
  --threads THREADS    Number of concurrent threads (default: 1)
  --delay DELAY        Delay between requests in seconds (default: 0.5)
  --rate-limit RATE_LIMIT
                       Requests per second per host (0 to disable, default: 10.0)
  --retries RETRIES    Number of retries for failed requests (default: 3)
  -v, --verbose        Increase verbosity (-v, -vv, -vvv)
  -q, --quiet          Suppress non-essential output

Examples

Concurrent Scanning

# Scan with 10 concurrent threads
python3 scanner.py hosts.txt --threads 10

JSON Output

# Output results in JSON format
python3 scanner.py hosts.txt --format json -o results.json

CSV Output

# Output results in CSV format
python3 scanner.py hosts.txt --format csv -o results.csv

Rate Limiting

# Set delay between requests and rate limit
python3 scanner.py hosts.txt --delay 1.0 --rate-limit 5.0

Verbose Mode

# Enable verbose output for debugging
python3 scanner.py hosts.txt -vv

Quiet Mode

# Suppress non-essential output
python3 scanner.py hosts.txt --quiet -o results.json

Output Formats

Text Format (Default)

Human-readable text output with scan summary and detailed results:

============================================================
SCAN SUMMARY
============================================================
Total hosts scanned: 5
Vulnerable hosts: 2
Safe hosts: 3
============================================================

[!] https://example.com - VULNERABLE
    Found 3 leaked source code(s)

[+] https://example2.com - Not vulnerable

JSON Format

Structured JSON output with full scan details:

{
  "summary": {
    "total_hosts": 5,
    "vulnerable_hosts": 2,
    "safe_hosts": 3
  },
  "results": [
    {
      "url": "https://example.com",
      "vulnerable": true,
      "chunk_paths": ["/_next/static/chunks/..."],
      "action_ids": ["abc123..."],
      "leaked_sources": [...]
    }
  ]
}

CSV Format

Comma-separated values for easy import into spreadsheets:

URL,Vulnerable,Chunks Found,Action IDs Found,Leaked Sources Count,Error
https://example.com,Yes,5,3,2,
https://example2.com,No,0,0,0,

How It Works

The scanner performs a three-step process:

  1. Discover Chunks: Fetches the target page and extracts JavaScript chunk file paths from /_next/static/chunks/ references
  2. Extract Action IDs: Downloads chunk files and extracts server action IDs (40-42 character hex strings)
  3. Exploit: Sends malicious requests with the $F1 payload to each action ID to trigger source code disclosure

Exit Codes

  • 0: No vulnerable hosts found
  • 1: One or more vulnerable hosts found

Security Considerations

  • Authorized Testing Only: Only use this tool on systems you own or have explicit written permission to test
  • Rate Limiting: Use appropriate rate limiting to avoid overwhelming target servers
  • Ethical Use: This tool is for security research and authorized penetration testing only

Troubleshooting

Connection Errors

If you encounter connection errors:

  • Check your internet connection
  • Verify the target URLs are accessible
  • Increase timeout: --timeout 30
  • Enable verbose mode: -vv to see detailed error messages

Rate Limiting Issues

If targets are blocking requests:

  • Increase delay: --delay 2.0
  • Lower rate limit: --rate-limit 2.0
  • Use fewer threads: --threads 1

Missing Dependencies

If you see import errors:

pip install -r requirements.txt

Note: tqdm is optional - the scanner will work without it but won't show progress bars.

License

This tool is provided for educational and authorized security testing purposes only.

Disclaimer

This tool is designed for security research and authorized penetration testing. Unauthorized use against systems you don't own or have permission to test is illegal and unethical. The authors are not responsible for any misuse of this tool.

References

  • CVE-2025-55183: Next.js RSC Source Code Disclosure Vulnerability
  • Next.js Documentation
Download Tool