
Security research lab for CVE-2025-55183 and CVE-2025-55184 in React Server Components
A comprehensive security testing environment for CVE-2025-55183 (Source Code Exposure) and CVE-2025-55184 (Denial of Service) vulnerabilities in React Server Components.
FOR EDUCATIONAL AND SECURITY RESEARCH PURPOSES ONLY
This repository contains deliberately vulnerable applications and exploitation tools. Only test on systems you own or have explicit written permission to test. Unauthorized testing is illegal and unethical.
Both vulnerabilities affect React Server Components versions 19.0.0 through 19.2.2, disclosed on December 11, 2025.
| Property | Value |
|---|---|
| Severity | Medium (CVSS 5.3) |
| Type | Information Disclosure |
| Impact | Server source code exposure |
| Authentication | None Required |
Attackers can coerce Server Action arguments to leak server-only source code by calling .toString() on server function objects. This exposes:
| Property | Value |
|---|---|
| Severity | High (CVSS 7.5) |
| Type | Denial of Service |
| Impact | Complete service outage |
| Authentication | None Required |
Specially crafted payloads create infinite promise recursion, causing the Node.js server to hang indefinitely. Results in:
| Aspect | CVE-2025-55183 | CVE-2025-55184 |
|---|---|---|
| Severity | Medium | High |
| Type | Information Disclosure | Denial of Service |
| Impact | Source code leakage | Server crash |
| Detection | Response contains code | Server timeout/hang |
| Recovery | Immediate | Requires restart |
TL;DR: The app IS vulnerable (React 19.0.0), but modern protections may prevent the actual crash in this demo environment.
CVE-2025-55184 is a REAL, CRITICAL vulnerability affecting React 19.0.0-19.2.2 in production environments. However, successfully demonstrating the DoS crash in a local demo can be challenging due to:
Even if the exploit doesn't crash the demo, you can verify vulnerability through:
cd vulnerable-app
npm list react react-dom
# Output shows:
[email protected] ← VULNERABLE VERSION
[email protected] ← VULNERABLE VERSION
If you see 19.0.0 through 19.2.2, the application IS vulnerable.
cd scanner
python scan.py http://localhost:3000
The scanner checks for:
git clone https://github.com/StealthMoud/react-server-cve-lab.git
cd react-server-cve-lab
# Start the app (vulnerable to both CVEs)
docker-compose up --build -d
# App available at: http://localhost:3000
cd scanner
# Install dependencies
pip install -r requirements.txt
# Scan for both vulnerabilities
python scan.py http://localhost:3000
# Scan only CVE-2025-55183
python scan.py --cve 55183 http://localhost:3000
# Scan only CVE-2025-55184
python scan.py --cve 55184 http://localhost:3000
# Scan multiple targets
python scan.py --file targets.txt
react-server-cve-lab/
├── README.md # This file
├── DOCUMENTATION.md # Complete technical documentation
├── LICENSE
├── .gitignore
├── docker-compose.yml
│
├── vulnerable-app/ # Vulnerable to BOTH CVEs
│ ├── Dockerfile
│ ├── package.json
│ ├── next.config.js
│ └── app/
│ ├── layout.js
│ ├── page.js
│ └── actions.js # Vulnerable server actions
│
├── scanner/
│ ├── requirements.txt
│ ├── scan.py # Scanner for both CVEs
│ └── README.md
│
└── exploits/
├── exploit-55183.py # PoC for CVE-2025-55183
├── exploit-55184.py # PoC for CVE-2025-55184
└── README.md
The application is a Next.js app running React 19.0.0 with Server Actions, vulnerable to both CVEs.
# Using Docker Compose (recommended)
docker-compose up --build -d
# Check if running
curl http://localhost:3000
# View logs
docker-compose logs -f
# Stop the app
docker-compose down
cd vulnerable-app
npm install
npm run build
npm start
The unified scanner detects both CVE-2025-55183 and CVE-2025-55184.
cd scanner
# Scan for both CVEs
python scan.py http://localhost:3000
# Scan specific CVE only
python scan.py --cve 55183 http://localhost:3000
python scan.py --cve 55184 http://localhost:3000
# Verbose output
python scan.py --verbose http://localhost:3000
# Custom timeout
python scan.py --timeout 10 http://example.com
# Scan multiple URLs from file
python scan.py --file targets.txt
# Save results to JSON
python scan.py --output results.json http://localhost:3000
# Disable SSL verification
python scan.py --no-verify https://self-signed.example.com
# Scan all CVEs with verbose output and save results
python scan.py --verbose --output scan-results.json http://localhost:3000
╔═══════════════════════════════════════════════════════════╗
║ React Server Components Vulnerability Scanner ║
║ CVE-2025-55183 & CVE-2025-55184 ║
╚═══════════════════════════════════════════════════════════╝
[*] Testing http://localhost:3000
[CVE-2025-55183] Source Code Exposure
[!] VULNERABLE: Source code leaked
Exposed Functions: 3
Code Length: 1247 characters
Contains Secrets: ✓ (API keys found)
[CVE-2025-55184] Denial of Service
[!] VULNERABLE: DoS attack successful
Status Code: 404
Content-Type: text/plain
Markers Found: ✓
============================================================
SUMMARY
============================================================
Total tested: 1
CVE-2025-55183 vulnerable: 1
CVE-2025-55184 vulnerable: 1
Both CVEs vulnerable: 1
Not vulnerable: 0
For comprehensive technical analysis of both vulnerabilities:
DOCUMENTATION.md - Complete technical documentation covering:
Both vulnerabilities are fixed in the same patch versions:
Update React to a patched version:
npm install [email protected] [email protected]
# or
npm install react@latest react-dom@latest
Update Next.js (if applicable):
npm install next@latest
Verify the fix:
npm list react react-dom next
python scanner/scan.py http://localhost:3000
| Package | Vulnerable Versions | Patched Versions |
|---|---|---|
| React | 19.0.0 - 19.2.2 | 19.0.3+, 19.1.4+, 19.2.3+ |
| Next.js 15.1.x | < 15.1.4 | 15.1.4+ |
| Next.js 15.0.x | < 15.0.4 | 15.0.4+ |
| Next.js 14.x | < 14.2.24 | 14.2.24+ |
# Run scanner to confirm fixes
cd scanner
python scan.py http://your-patched-app.com
# Expected output:
# [+] CVE-2025-55183: NOT VULNERABLE
# [+] CVE-2025-55184: NOT VULNERABLE
Contributions are welcome! Areas for improvement:
Please feel free to submit a Pull Request.
This project is licensed under the MIT License - see the LICENSE file for details.
If you find this repository helpful for your security research, please consider giving it a star!