Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
react-server-cve-lab — Security research lab for CVE-2025-55183 and CVE-2025-55184 in React Server Components | Kitploit
Tools/GitHubGitHub/stealthmoud/react-server-cve-lab
Vulnerability AnalysisExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubstealthmoud/react-server-cve-lab

react-server-cve-lab

Security research lab for CVE-2025-55183 and CVE-2025-55184 in React Server Components

View Repository
539 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

React Server Components Security Lab (CVE-2025-55183 & CVE-2025-55184)

License: MIT React Version CVE-2025-55183 CVE-2025-55184

A comprehensive security testing environment for CVE-2025-55183 (Source Code Exposure) and CVE-2025-55184 (Denial of Service) vulnerabilities in React Server Components.

⚠️ Disclaimer

FOR EDUCATIONAL AND SECURITY RESEARCH PURPOSES ONLY

This repository contains deliberately vulnerable applications and exploitation tools. Only test on systems you own or have explicit written permission to test. Unauthorized testing is illegal and unethical.

📋 Table of Contents

  • About the Vulnerabilities
  • Quick Start
  • Repository Structure
  • Vulnerable Application
  • Scanner Usage
  • Detailed Documentation
  • Remediation
  • License

🔍 About the Vulnerabilities

Both vulnerabilities affect React Server Components versions 19.0.0 through 19.2.2, disclosed on December 11, 2025.

CVE-2025-55183: Source Code Exposure (Medium Severity)

PropertyValue
SeverityMedium (CVSS 5.3)
TypeInformation Disclosure
ImpactServer source code exposure
AuthenticationNone Required

Attackers can coerce Server Action arguments to leak server-only source code by calling .toString() on server function objects. This exposes:

  • Business logic and algorithms
  • Hardcoded API keys or secrets
  • Internal implementation details
  • Database queries and schema information

CVE-2025-55184: Denial of Service (High Severity)

PropertyValue
SeverityHigh (CVSS 7.5)
TypeDenial of Service
ImpactComplete service outage
AuthenticationNone Required

Specially crafted payloads create infinite promise recursion, causing the Node.js server to hang indefinitely. Results in:

  • Complete service unavailability
  • CPU exhaustion
  • Blocked event loop
  • Manual restart required

Comparison

AspectCVE-2025-55183CVE-2025-55184
SeverityMediumHigh
TypeInformation DisclosureDenial of Service
ImpactSource code leakageServer crash
DetectionResponse contains codeServer timeout/hang
RecoveryImmediateRequires restart

⚠️ Important: About CVE-2025-55184 (DoS) in This Demo

Why the DoS Might Not Crash the Demo App

TL;DR: The app IS vulnerable (React 19.0.0), but modern protections may prevent the actual crash in this demo environment.

The Reality Check

CVE-2025-55184 is a REAL, CRITICAL vulnerability affecting React 19.0.0-19.2.2 in production environments. However, successfully demonstrating the DoS crash in a local demo can be challenging due to:

1. Next.js Built-in Protection

  • Next.js 15.x includes error boundaries that catch and recover from many crashes
  • Automatic error recovery mechanisms prevent infinite recursion
  • Production mode has different error handling than the vulnerable code path

2. Docker Isolation

  • Containerization adds process isolation
  • Resource limits prevent complete system hang
  • Docker's init system can detect and restart hung processes

3. Development vs Production

  • The exact vulnerable code path requires specific production configurations
  • Dev/demo environments have additional safety mechanisms
  • Race conditions and timing are different in containers

How to Verify the Vulnerability IS Present

Even if the exploit doesn't crash the demo, you can verify vulnerability through:

Method 1: Version Check (Most Reliable)

root@kitploit:~
cd vulnerable-app
npm list react react-dom

# Output shows:
[email protected]        ← VULNERABLE VERSION
[email protected]    ← VULNERABLE VERSION

If you see 19.0.0 through 19.2.2, the application IS vulnerable.

Method 2: Scanner Detection

root@kitploit:~
cd scanner
python scan.py http://localhost:3000

The scanner checks for:

  • ✅ React version in vulnerable range
  • ✅ Server Actions enabled
  • ✅ Proper server response headers
  • ✅ Exploitable endpoint patterns

🚀 Quick Start

Prerequisites

  • Docker & Docker Compose
  • Python 3.7+
  • Git

1. Clone the Repository

root@kitploit:~
git clone https://github.com/StealthMoud/react-server-cve-lab.git
cd react-server-cve-lab

2. Start the Vulnerable Application

root@kitploit:~
# Start the app (vulnerable to both CVEs)
docker-compose up --build -d

# App available at: http://localhost:3000

3. Run the Scanner

root@kitploit:~
cd scanner

# Install dependencies
pip install -r requirements.txt

# Scan for both vulnerabilities
python scan.py http://localhost:3000

# Scan only CVE-2025-55183
python scan.py --cve 55183 http://localhost:3000

# Scan only CVE-2025-55184
python scan.py --cve 55184 http://localhost:3000

# Scan multiple targets
python scan.py --file targets.txt

📁 Repository Structure

root@kitploit:~
react-server-cve-lab/
├── README.md                          # This file
├── DOCUMENTATION.md                   # Complete technical documentation
├── LICENSE
├── .gitignore
├── docker-compose.yml
│
├── vulnerable-app/                    # Vulnerable to BOTH CVEs
│   ├── Dockerfile
│   ├── package.json
│   ├── next.config.js
│   └── app/
│       ├── layout.js
│       ├── page.js
│       └── actions.js                 # Vulnerable server actions
│
├── scanner/
│   ├── requirements.txt
│   ├── scan.py                        # Scanner for both CVEs
│   └── README.md
│
└── exploits/
    ├── exploit-55183.py               # PoC for CVE-2025-55183
    ├── exploit-55184.py               # PoC for CVE-2025-55184
    └── README.md

🎯 Vulnerable Application

The application is a Next.js app running React 19.0.0 with Server Actions, vulnerable to both CVEs.

Features

  • Server Actions: Multiple endpoints demonstrating both vulnerabilities
  • Realistic Code: Simulates real-world patterns with secrets
  • Easy Testing: Simple UI for manual testing
  • Docker-based: Isolated, reproducible environment

Starting the App

root@kitploit:~
# Using Docker Compose (recommended)
docker-compose up --build -d

# Check if running
curl http://localhost:3000

# View logs
docker-compose logs -f

# Stop the app
docker-compose down

Manual Setup (Without Docker)

root@kitploit:~
cd vulnerable-app
npm install
npm run build
npm start

🔎 Scanner Usage

The unified scanner detects both CVE-2025-55183 and CVE-2025-55184.

Basic Usage

root@kitploit:~
cd scanner

# Scan for both CVEs
python scan.py http://localhost:3000

# Scan specific CVE only
python scan.py --cve 55183 http://localhost:3000
python scan.py --cve 55184 http://localhost:3000

Advanced Options

root@kitploit:~
# Verbose output
python scan.py --verbose http://localhost:3000

# Custom timeout
python scan.py --timeout 10 http://example.com

# Scan multiple URLs from file
python scan.py --file targets.txt

# Save results to JSON
python scan.py --output results.json http://localhost:3000

# Disable SSL verification
python scan.py --no-verify https://self-signed.example.com

# Scan all CVEs with verbose output and save results
python scan.py --verbose --output scan-results.json http://localhost:3000

Example Output

root@kitploit:~
╔═══════════════════════════════════════════════════════════╗
║     React Server Components Vulnerability Scanner        ║
║         CVE-2025-55183 & CVE-2025-55184                  ║
╚═══════════════════════════════════════════════════════════╝

[*] Testing http://localhost:3000

[CVE-2025-55183] Source Code Exposure
[!] VULNERABLE: Source code leaked
    Exposed Functions: 3
    Code Length: 1247 characters
    Contains Secrets: ✓ (API keys found)

[CVE-2025-55184] Denial of Service
[!] VULNERABLE: DoS attack successful
    Status Code: 404
    Content-Type: text/plain
    Markers Found: ✓

============================================================
SUMMARY
============================================================
Total tested: 1
CVE-2025-55183 vulnerable: 1
CVE-2025-55184 vulnerable: 1
Both CVEs vulnerable: 1
Not vulnerable: 0

📚 Detailed Documentation

For comprehensive technical analysis of both vulnerabilities:

DOCUMENTATION.md - Complete technical documentation covering:

  • Detailed vulnerability analysis for both CVEs
  • Root cause explanations
  • Exploitation techniques with examples
  • Impact assessments
  • Detection strategies
  • Step-by-step remediation
  • Prevention best practices
  • Code samples and PoCs

🛡️ Remediation

Immediate Actions Required

Both vulnerabilities are fixed in the same patch versions:

  1. Update React to a patched version:

    root@kitploit:~
    npm install [email protected] [email protected]
    # or
    npm install react@latest react-dom@latest
    
  2. Update Next.js (if applicable):

    root@kitploit:~
    npm install next@latest
    
  3. Verify the fix:

    root@kitploit:~
    npm list react react-dom next
    python scanner/scan.py http://localhost:3000
    

Patched Versions

PackageVulnerable VersionsPatched Versions
React19.0.0 - 19.2.219.0.3+, 19.1.4+, 19.2.3+
Next.js 15.1.x< 15.1.415.1.4+
Next.js 15.0.x< 15.0.415.0.4+
Next.js 14.x< 14.2.2414.2.24+

Verification After Patching

root@kitploit:~
# Run scanner to confirm fixes
cd scanner
python scan.py http://your-patched-app.com

# Expected output:
# [+] CVE-2025-55183: NOT VULNERABLE
# [+] CVE-2025-55184: NOT VULNERABLE

🔒 Security Best Practices

Prevent CVE-2025-55183 (Source Code Exposure)

  1. Input Validation: Always validate Server Action inputs
  2. Never Store Secrets in Code: Use environment variables
  3. Code Obfuscation: Consider build-time obfuscation for sensitive logic
  4. Regular Audits: Review Server Actions for sensitive data

Prevent CVE-2025-55184 (DoS)

  1. Rate Limiting: Implement request rate limits
  2. Timeouts: Set appropriate timeouts for all async operations
  3. Health Checks: Implement robust health monitoring
  4. Circuit Breakers: Prevent cascading failures

General Recommendations

  • Keep React and Next.js updated
  • Subscribe to security advisories
  • Implement Web Application Firewall (WAF)
  • Regular security scanning in CI/CD
  • Incident response plan for both disclosure and DoS

🤝 Contributing

Contributions are welcome! Areas for improvement:

  • Additional test cases
  • Improved detection methods
  • Better exploitation examples
  • Enhanced documentation

Please feel free to submit a Pull Request.

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🔗 References

Official Advisories

  • React Security Blog
  • Vercel Security Bulletin

CVE Details

  • CVE-2025-55183 (NVD)
  • CVE-2025-55184 (NVD)

Additional Resources

  • CWE-502: Deserialization of Untrusted Data
  • CWE-200: Information Exposure
  • React Server Components Docs

⭐ Support

If you find this repository helpful for your security research, please consider giving it a star!

📧 Contact

  • Issues: GitHub Issues
  • Security: Please report vulnerabilities responsibly

Download Tool