Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182-Scanner — A standalone GUI tool to detect and demonstrate the **React Server Components Remote Code Execution (RCE)** vulnerability (CVE-2025-55182) in Next.js applications. | Kitploit
Tools/GitHubGitHub/sainionhacks/cve-2025-55182-scanner
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubsainionhacks/cve-2025-55182-scanner

CVE-2025-55182-Scanner

A standalone GUI tool to detect and demonstrate the **React Server Components Remote Code Execution (RCE)** vulnerability (CVE-2025-55182) in Next.js applications.

View Repository
219 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️ CVE-2025-55182 Scanner (React2Shell)

Platform License Status

Developed by: SainiON Hacks

A standalone GUI tool to detect and demonstrate the React Server Components Remote Code Execution (RCE) vulnerability (CVE-2025-55182) in Next.js applications.

image

📺 Demo & Tutorial

Watch the full breakdown and tool demonstration on my YouTube channel: Subscribe to SainiON Hacks


📖 About The Tool

This tool automates the "React2Shell" exploit process. It allows security researchers to test if a Next.js application is vulnerable to Remote Code Execution without needing to write complex scripts or manually manipulate HTTP headers.

How it works:

  1. It constructs a malicious multipart/form-data payload.
  • It injects a specific gadget chain into the React "Flight" protocol.
  • It captures the server's response to display the output of your command (e.g., whoami).
  • ✨ Features

    • No Installation Required: Portable .exe file.
    • User-Friendly Interface: Simple GUI with Dark Mode styling.
    • Real-Time Output: View command results directly in the log window.
    • Threaded Scanning: The tool remains responsive while the scan runs.
    • Auto-Correction: Automatically handles URL formatting.

    🚀 How to Run

    1. Download: Get the SainiON_Scanner.exe file.
    2. Open: Double-click the file to launch the tool.
    3. Configure:
      • Target URL: Enter the full URL of the target (e.g., http://localhost:3000).
      • Command: Enter the system command to execute (default is id or whoami).
    4. Scan: Click "Execute Payload".
    5. Results: Check the black console window at the bottom for the command output.

    ⚠️ Troubleshooting / Antivirus

    Because this is a security tool designed to simulate an attack:

    • Windows Defender or other Antivirus software may flag it as a threat.
    • Solution: You may need to "Allow" the file or add an exclusion to your antivirus to run it.

    ⚠️ Disclaimer

    This tool is provided for EDUCATIONAL and RESEARCH purposes only.

    The author, SainiON Hacks, is not responsible for any misuse of this tool. Usage of this tool for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state, and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program.


    🤝 Connect

    • YouTube: SainiON Hacks
    Download Tool