
A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python and Tkinter, featuring a sleek neon-themed interface for scanning targets, executing shell commands, and viewing live console output.
A modern, neon-themed GUI tool for security testing React2Shell (CVE-2025-55182) on React Server Components / Next.js applications.
Built with Python + CustomTkinter, it lets you:
⚠️ This is a security research & blue-team tool, not a mass scanner.
Use it only on systems you own or are explicitly authorized to test.
This project is provided for educational, defensive, and research purposes only.
If you are unsure whether you are allowed to test a system, stop right now.
React2Shell (CVE-2025-55182) is a critical vulnerability in and frameworks implementing the , most notably .
Key points:
For detailed technical write-ups, see:
🖥 Modern GUI
🔍 Target Scanner
Vulnerable – appears exploitable via React2ShellAppears safe – exploit pattern not observed💣 Command Execution (for confirmed vulnerable systems)
⚡ Quick Commands
whoami, hostname, id, etc.)🧾 Verbose Logging
[HH:MM:SS] [LEVEL] message