Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182-Scanner β€” Scanner and exploit toolkit for CVE-2025-55182, a critical pre-auth RCE in React Server Components. Includes detection, interactive shell, Docker deployment, and educational technical analysis. | Kitploit
Tools/GitHubGitHub/stealthmoud/cve-2025-55182-scanner
Vulnerability ScannersExploitationWeb Application ExploitationPenetration TestingLearning & EducationPayload Development
GitHubstealthmoud/cve-2025-55182-scanner

CVE-2025-55182-Scanner

Scanner and exploit toolkit for CVE-2025-55182, a critical pre-auth RCE in React Server Components. Includes detection, interactive shell, Docker deployment, and educational technical analysis.

View Repository
8109 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

CVE-2025-55182 - React Server Components RCE Scanner

Severity CVE License

A comprehensive security testing toolkit for CVE-2025-55182, a critical pre-authentication remote code execution vulnerability in React Server Components.


πŸŽ“ NEW: Complete Educational Guide Available!

Want to understand this vulnerability 100%?

πŸ“– Read our Complete Technical Analysis - Everything you need to know:

  • Why React runs on the server (not just browser!)
  • How the attack works with visual diagrams
  • Every line of the exploit explained
  • From beginner concepts to advanced exploitation
  • No prerequisites required!

Perfect for: Security reports, training materials, threat analysis, or just learning!


πŸ” Overview

This vulnerability affects React Server Components versions 19.0.0 through 19.2.0, impacting:

  • react-server-dom-parcel
  • react-server-dom-turbopack
  • react-server-dom-webpack

Impact: Unauthenticated attackers can execute arbitrary code remotely through unsafe deserialization of HTTP request payloads to Server Function endpoints.

πŸ“š Want to Understand This Vulnerability Completely?

πŸ‘‰ Read the Complete Technical Analysis - A comprehensive guide covering:

  • βœ… Why React runs on the server (not just the browser!)
  • βœ… What are Server Components and how they work
  • βœ… Step-by-step attack flow with visual diagrams
  • βœ… Complete payload breakdown - every line explained
  • βœ… Prototype pollution explained from basics to exploitation
  • βœ… Real-world proof of concept with examples
  • βœ… Detection methods and security indicators

Perfect for:

  • πŸŽ“ Learning how modern web vulnerabilities work
  • πŸ”’ Security professionals doing threat analysis
  • πŸ‘¨β€πŸ’» Developers wanting to understand the risk
  • πŸ“Š Creating security reports and presentations

No prior knowledge required - starts from basics and builds up to advanced exploitation techniques!


⚠️ Legal Disclaimer

FOR EDUCATIONAL AND AUTHORIZED SECURITY TESTING ONLY

This tool is intended solely for:

  • Security research
  • Authorized penetration testing
  • Educational purposes

Warning: Unauthorized access to computer systems is illegal. Users are responsible for complying with all applicable laws and regulations. The authors assume no liability for misuse of this tool.


🎯 Quick Start Options

Option 1: Standalone Exploit Script (Fastest)

No dependencies required! Single bash script for quick testing.

πŸ‘‰ EXPLOIT_SCRIPT.md - Standalone script that:

  • βœ… Tests vulnerability with one command
  • βœ… Provides interactive shell
  • βœ… Works without Nuclei or Docker
  • βœ… Supports single or multiple targets
# Single target
./exploit-cve-2025-55182.sh http://target.com

# Multiple targets
./exploit-cve-2025-55182.sh -f targets.txt

Option 2: Full Scanner Suite (Most Features)

Complete toolkit with Docker, Web UI, and Nuclei integration. Continue reading below for installation.


πŸš€ Features

FeatureDescription
🐳 Docker SupportOne-command deployment with Docker Compose
🌐 Web InterfaceUser-friendly web UI for non-technical users
πŸ” Vulnerable Test EnvironmentSpin up a local vulnerable app for safe testing
🎯 Remote ScanningTest external targets for vulnerability
⚑ Interactive ShellExecute OS commands and see results in real-time
πŸ“Š Multiple Scan ModesDetection-only or full exploitation
πŸ“ Detailed ReportingJSON and text output formats
πŸ”§ Nuclei IntegrationLeverage ProjectDiscovery's powerful scanner

πŸ“‹ Prerequisites

Choose your installation method:

Docker (Recommended)

  • Docker Desktop installed and running

Local Installation

  • Node.js 18+ (for vulnerable app)
  • Nuclei scanner (install via Homebrew or Go)
  • macOS, Linux, or Windows with WSL2

πŸ› οΈ Installation

Quick Start with Docker

# Clone repository
git clone https://github.com/StealthMoud/CVE-2025-55182-Scanner.git
cd CVE-2025-55182-Scanner

# Start scanner
docker compose up

# Access web interface at http://localhost:3001

Local Installation

# Clone repository
git clone https://github.com/StealthMoud/CVE-2025-55182-Scanner.git
cd CVE-2025-55182-Scanner

# Install Nuclei (macOS)
brew install nuclei

# Make scripts executable
chmod +x scripts/*.sh

πŸ“– Detailed Setup: See SETUP_GUIDE.md for step-by-step instructions
⚑ Quick Reference: See QUICKSTART.md for common use cases


πŸ“– Usage

🐳 Docker Mode

Start Web Interface:

docker compose up
# Open browser: http://localhost:3001

Start with Vulnerable Test App:

docker compose --profile with-vulnerable-app up
# Scanner:       http://localhost:3001
# Vulnerable app: http://localhost:3000

Important for Docker users: When scanning from Docker, use:

  • http://host.docker.internal:3000 to scan apps on your host machine
  • http://vulnerable-app:3000 to scan the containerized vulnerable app
  • https://example.com for external targets

🌐 Web Interface

  1. Navigate to http://localhost:3001
  2. Select mode:
    • Vulnerability Detection - Check if target is vulnerable
    • Command Execution - Execute OS commands on vulnerable targets
  3. Enter target URL
  4. Check authorization checkbox
  5. Click Start Scan or Execute Command
  6. View results in real-time

πŸ’» Command Line Interface

Test Local Vulnerable Application

Create and test against a local vulnerable app:

# Terminal 1: Start vulnerable app
./scripts/setup-vulnerable-app.sh
# App will run on http://localhost:3000

# Terminal 2: Test it
./scripts/test-local.sh

# Execute custom commands
./scripts/test-local.sh "whoami"
./scripts/test-local.sh "pwd"
./scripts/test-local.sh "ls -la"

Test Remote Target

# Basic scan
./scripts/test-remote.sh https://target.com

# With command execution
./scripts/test-remote.sh https://target.com "id"

Scan Multiple Targets

# Create targets file
cat > targets.txt << EOF
https://target1.com
https://target2.com
https://target3.com
EOF

# Scan all targets
./scripts/test-multiple.sh targets.txt

🎯 Advanced: Manual Nuclei Commands

Basic vulnerability detection:

nuclei -t templates/cve-2025-55182.yaml -u http://localhost:3000 -v

Execute custom commands:

nuclei -t templates/cve-2025-55182-interactive.yaml \
  -u http://localhost:3000 \
  -var cmd="whoami" \
  -v

Scan multiple targets:

nuclei -t templates/cve-2025-55182.yaml -l targets.txt -v

πŸ“ Project Structure

Download Tool