Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
React2Shell — Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization. | Kitploit
Tools/GitHubGitHub/phanhoangkhang/react2shell
Static AnalysisVulnerability ScannersDynamic Analysis (Sandboxing)Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityLearning & EducationLabs & Practice
GitHubphanhoangkhang/react2shell

React2Shell

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

231 month agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Docker Lab & Detection Scanner & PoC Validation: React2Shell (CVE-2025-55182)

Disclaimer: This repository and its PoC artifacts are created strictly for educational, research, and defensive security demonstration purposes within an isolated lab environment. Unsanctioned testing against external systems is strictly prohibited.


1. Project Governance & Authorization Boundary

Project Purpose

This repository provides a reproducible, dual-container Docker environment designed to analyze, exploit, and validate mitigations for the React Server Components (RSC) Flight Protocol Deserialization vulnerability (popularly referenced as React2Shell / CVE-2025-55182). The lab demonstrates post-exploitation impact on an unpatched Next.js build and proves mitigation efficacy on a patched build.

Target

  • In-Scope Targets:
    • http://127.0.0.1:3001 (react2shell-vulnerable container)
    • http://127.0.0.1:3002 (react2shell-patched container)
  • Out-of-Scope: Any external domain, public network interface, host machine operating system, or cloud infrastructure.

Lab Safety Controls

  • Network Isolation: All containers run within a private Docker bridge network with outbound internet routing disabled (internal: true).
  • Loopback Binding: Exposed ports are strictly bound to 127.0.0.1 (localhost) to prevent external LAN accessibility.
  • Dummy Secrets: Simulated credentials (DUMMY_SECRET=LAB_VULNERABLE_SECRET_DO_NOT_USE_12345) are utilized for exfiltration testing to eliminate sensitive data exposure.

2. Environment Setup & Operational Instructions

Prerequisites

  • Docker Desktop (Engine 24.0.0+, Compose v2.20.0+)
  • Python (3.8+ — Standard library only for base automation)
  • cURL (WSL, Linux, or PowerShell built-in)

Installation

Clone the repository and verify your local environment:

git clone https://github.com/PhanHoangKhang/React2Shell.git

Lab Startup

Navigate to the lab/ directory and initialize both dual-build containers:

cd lab
docker-compose up -d --build
cd ..

Vulnerability Detection

Run the detection scanner in both labs:

1. Scan the patched lab

python src/react2shell_scanner.py lab/patched

2. Scan the vulnerable lab

python src/react2shell_scanner.py lab/vulnerable

Lab Stop

cd lab
docker-compose stop
cd ..

Dynamic Exploitation & Validation (PoC)

To execute the exploit validation tests and verify exfiltration artifacts, please refer to the detailed step-by-step PoC guide:

👉 View PoC & Vulnerability Validation Guide (poc_reference.md)

3. Dependencies, Lockfile Format & Version Rules

Dependency Matrix

Target ServiceFramework / PackageInstalled VersionLockfile Format
Vulnerable Target (:3001)Next.js15.0.0-rc.1package-lock.json (Lockfile Version 3)
React / React-DOM19.0.0-rc-65a56d0e-20241020NPM Registry Release
Patched Target (:3002)Next.js15.0.3 (Stable)package-lock.json (Lockfile Version 3)
React / React-DOM19.0.0 (Stable)NPM Registry Release

Lockfile Selection & Version-Rule Sources

  • Selected Lockfile Format: NPM package-lock.json (v3 format). The static scanner prioritizes parsing the resolved dependency tree inside packages["node_modules/next"] for accurate detection.
  • Version-Rule Sources: Rule definitions for CVE-2025-55182 are derived from official Next.js Security Advisories, marking all Next.js versions < 15.0.3 (including 15.0.0-rc builds) as vulnerable to RSC Flight Protocol deserialization.

PoC Source & Reference Commit

  • PoC Source: Derived from public research on React Server Components (RSC) Flight Chunk Deserialization Gadgets.
Download Tool