
Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.
Disclaimer: This repository and its PoC artifacts are created strictly for educational, research, and defensive security demonstration purposes within an isolated lab environment. Unsanctioned testing against external systems is strictly prohibited.
This repository provides a reproducible, dual-container Docker environment designed to analyze, exploit, and validate mitigations for the React Server Components (RSC) Flight Protocol Deserialization vulnerability (popularly referenced as React2Shell / CVE-2025-55182). The lab demonstrates post-exploitation impact on an unpatched Next.js build and proves mitigation efficacy on a patched build.
http://127.0.0.1:3001 (react2shell-vulnerable container)http://127.0.0.1:3002 (react2shell-patched container)internal: true).127.0.0.1 (localhost) to prevent external LAN accessibility.DUMMY_SECRET=LAB_VULNERABLE_SECRET_DO_NOT_USE_12345) are utilized for exfiltration testing to eliminate sensitive data exposure.24.0.0+, Compose v2.20.0+)3.8+ — Standard library only for base automation)Clone the repository and verify your local environment:
git clone https://github.com/PhanHoangKhang/React2Shell.git
Navigate to the lab/ directory and initialize both dual-build containers:
cd lab
docker-compose up -d --build
cd ..
Run the detection scanner in both labs:
python src/react2shell_scanner.py lab/patched
python src/react2shell_scanner.py lab/vulnerable
cd lab
docker-compose stop
cd ..
To execute the exploit validation tests and verify exfiltration artifacts, please refer to the detailed step-by-step PoC guide:
👉 View PoC & Vulnerability Validation Guide (poc_reference.md)
| Target Service | Framework / Package | Installed Version | Lockfile Format |
|---|---|---|---|
Vulnerable Target (:3001) | Next.js | 15.0.0-rc.1 | package-lock.json (Lockfile Version 3) |
| React / React-DOM | 19.0.0-rc-65a56d0e-20241020 | NPM Registry Release | |
Patched Target (:3002) | Next.js | 15.0.3 (Stable) | package-lock.json (Lockfile Version 3) |
| React / React-DOM | 19.0.0 (Stable) | NPM Registry Release |
package-lock.json (v3 format). The static scanner prioritizes parsing the resolved dependency tree inside packages["node_modules/next"] for accurate detection.< 15.0.3 (including 15.0.0-rc builds) as vulnerable to RSC Flight Protocol deserialization.