Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182 — Proof-of-concept exploit for CVE-2025-55182, a critical unauthenticated RCE in React Server Components. Includes automated Python exploit, technical analysis, detection rules, and lab environment setup for authorized security testing. | Kitploit
Tools/GitHubGitHub/tinashelorenzi/cve-2025-55182
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingIntrusion DetectionLearning & EducationRed TeamingPayload DevelopmentLabs & Practice
GitHubtinashelorenzi/cve-2025-55182

CVE-2025-55182

Proof-of-concept exploit for CVE-2025-55182, a critical unauthenticated RCE in React Server Components. Includes automated Python exploit, technical analysis, detection rules, and lab environment setup for authorized security testing.

View Repository
179 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

React2Shell (CVE-2025-55182) - Proof of Concept

A comprehensive proof-of-concept exploit and educational resource for CVE-2025-55182, a critical remote code execution vulnerability affecting React Server Components with a CVSS score of 10.0.

Python Version License CVSS

Legal Disclaimer

FOR EDUCATIONAL AND AUTHORIZED TESTING PURPOSES ONLY

This tool is provided for educational purposes and authorized security testing only. Unauthorized access to computer systems is illegal under various laws including the Computer Fraud and Abuse Act (CFAA) in the United States and similar legislation worldwide.

You must:

  • Only use this tool on systems you own or have explicit written authorization to test
  • Comply with all applicable local, state, and federal laws
  • Use this tool responsibly and ethically

The author and contributors:

  • Are not responsible for any misuse or damage caused by this tool
  • Do not endorse or encourage unauthorized access to computer systems
  • Provide this tool strictly for educational and defensive security purposes

By using this tool, you acknowledge that you understand and agree to these terms.

📋 Table of Contents

  • Overview
  • Vulnerability Details
  • Affected Versions
  • Technical Analysis
  • Installation
  • Usage
  • Detection
  • Remediation
  • Lab Environment Setup
  • References
  • Contributing
  • Author

🎯 Overview

React2Shell is a critical vulnerability discovered in December 2025 that affects React Server Components (RSC) and frameworks implementing them, particularly Next.js. The vulnerability allows unauthenticated remote code execution through a single crafted HTTP request.

This repository contains:

  • ✅ Automated Python exploit script
  • ✅ Detailed technical analysis
  • ✅ Detection rules (Snort, OSQuery)
  • ✅ Lab environment setup guide
  • ✅ Comprehensive documentation

🔍 Vulnerability Details

FieldDetails
CVE IDCVE-2025-55182
CVSS Score10.0 (Critical)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ImpactComplete system compromise (RCE)
Disclosure DateDecember 2025

What Makes This Critical?

  1. No Authentication Required - Exploitable by any unauthenticated attacker
  2. Default Configurations Vulnerable - Standard Next.js apps created with create-next-app are exploitable
  3. High Reliability - Near 100% exploitation success rate
  4. Wide Attack Surface - 571,000+ public servers running React components (Shodan data)
  5. Severe Impact - Full remote code execution with Node.js process privileges

📦 Affected Versions

React Server Components

Vulnerable versions:

  • react-server-dom-webpack: 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • react-server-dom-parcel: 19.0.0, 19.1.0, 19.1.1, 19.2.0
  • react-server-dom-turbopack: 19.0.0, 19.1.0, 19.1.1, 19.2.0

Patched versions:

  • React 19.0.1
  • React 19.1.2
  • React 19.2.1

Next.js

Vulnerable versions:

  • All versions ≥14.3.0-canary.77
  • All 15.x releases (pre-patch)
  • All 16.x releases (pre-patch)

Patched versions:

  • Check Next.js releases for updated versions incorporating React patches

Other Affected Frameworks

  • React Router (when using RSC mode)
  • Waku
  • Redwood SDK
  • Various RSC-enabled frameworks

🔬 Technical Analysis

Root Cause

The vulnerability exists in the requireModule function within React Server Components' deserialization logic:

function requireModule(metadata) {  
  var moduleExports = __webpack_require__(metadata[0]);  
  return moduleExports[metadata[2]];  // VULNERABLE LINE - Prototype chain traversal
}

The flaw allows attackers to traverse JavaScript's prototype chain through the React Flight protocol, accessing the Function constructor via properties like constructor.constructor, enabling arbitrary code execution.

Exploitation Chain

  1. Fake Chunk Creation - Attacker sends multipart form data with a crafted chunk object
  2. Prototype Pollution - Exploits __proto__ to create self-referential structure
  3. Blob Handler Abuse - Triggers React's internal Blob deserialization handler
  4. Function Constructor Access - Chains through constructor.constructor to access Function()
  5. Code Execution - Injects arbitrary JavaScript via child_process.execSync()

Attack Flow Diagram

┌─────────────────────────────────────────────────────────────┐
│  Attacker sends multipart/form-data with Next-Action header │
└──────────────────────┬──────────────────────────────────────┘
                       │
                       ▼
┌─────────────────────────────────────────────────────────────┐
│  Server deserializes payload via React Flight protocol      │
└──────────────────────┬──────────────────────────────────────┘
                       │
                       ▼
┌─────────────────────────────────────────────────────────────┐
│  Fake chunk object with __proto__ pollution processed       │
└──────────────────────┬──────────────────────────────────────┘
                       │
                       ▼
┌─────────────────────────────────────────────────────────────┐
│  Blob handler invokes _formData.get(_prefix + id)           │
└──────────────────────┬──────────────────────────────────────┘
                       │
                       ▼
┌─────────────────────────────────────────────────────────────┐
│  Resolves to Function("malicious_code")                     │
└──────────────────────┬──────────────────────────────────────┘
                       │
                       ▼
┌─────────────────────────────────────────────────────────────┐
│  Arbitrary code executed with Node.js process privileges    │
└─────────────────────────────────────────────────────────────┘

🚀 Installation

Requirements

  • Python 3.7 or higher
  • requests library

Setup

# Clone the repository
git clone https://github.com/yourusername/react2shell-poc.git
cd react2shell-poc

# Install dependencies
pip install -r requirements.txt

# Make script executable (Linux/macOS)
chmod +x react2shell.py

Requirements.txt

requests>=2.31.0
urllib3>=2.0.0

💻 Usage

Basic Usage

python3 react2shell.py

Interactive Session

╔═══════════════════════════════════════════════════════════╗
║           React2Shell (CVE-2025-55182) PoC                ║
║                 CVSS 10.0 - Critical RCE                  ║
║                                                           ║
║  Affected: React 19.0.0, 19.1.0, 19.1.1, 19.2.0          ║
║           Next.js ≥14.3.0-canary.77, 15.x, 16.x          ║
║                                                           ║
║  Cerberus Secure - Lab Use Only                          ║
╚═══════════════════════════════════════════════════════════╝

[?] Enter target information:
    Host (e.g., localhost or 192.168.1.100): localhost
    Port (e.g., 3000): 3000

[React2Shell]> id
[*] Target: http://localhost:3000/
[*] Command: id
[*] Building exploit payload...
[*] Sending exploit request...
[+] Response Status Code: 200
[*] Parsing response...

╔═══════════════════════════════════════════════════════════╗
║                    COMMAND OUTPUT                         ║
╚═══════════════════════════════════════════════════════════╝
uid=1000(node) gid=1000(node) groups=1000(node)

[React2Shell]> whoami
[React2Shell]> pwd
[React2Shell]> ls -la
[React2Shell]> exit
Download Tool