
A standalone GUI tool to detect and demonstrate the **React Server Components Remote Code Execution (RCE)** vulnerability (CVE-2025-55182) in Next.js applications.
Developed by: SainiON Hacks
A standalone GUI tool to detect and demonstrate the React Server Components Remote Code Execution (RCE) vulnerability (CVE-2025-55182) in Next.js applications.
Watch the full breakdown and tool demonstration on my YouTube channel: Subscribe to SainiON Hacks
This tool automates the "React2Shell" exploit process. It allows security researchers to test if a Next.js application is vulnerable to Remote Code Execution without needing to write complex scripts or manually manipulate HTTP headers.
How it works:
multipart/form-data payload.whoami)..exe file.SainiON_Scanner.exe file.http://localhost:3000).id or whoami).Because this is a security tool designed to simulate an attack:
This tool is provided for EDUCATIONAL and RESEARCH purposes only.
The author, SainiON Hacks, is not responsible for any misuse of this tool. Usage of this tool for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state, and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program.