
A hybrid security scanner for detecting CVE-2025-55182 in Next.js and Waku applications. Features combined static code analysis and safe dynamic verification for DevSecOps workflows.
A professional, hybrid security scanner designed to bridge static analysis and dynamic exploitation capabilities for CVE-2025-55182. This tool serves both developers (shift-left security) and security professionals (production testing).
package.json and source code for vulnerable Next.js/Waku versions and dangerous RSC patterns.Prerequisites: Python 3.8+
Install Dependencies:
pip install -r requirements.txt
Static Analysis (Codebase) Scan a local project directory for vulnerable dependencies and code patterns.
python cve_2025_55182_scan.py --static /path/to/project
Dynamic Analysis (Live Site) Safely test a running application URL.
python cve_2025_55182_scan.py --dynamic http://localhost:3000
Hybrid Scan Combine static and dynamic results for a full report.
python cve_2025_55182_scan.py --hybrid /path/to/project --url http://localhost:3000
CI/CD Pipeline Mode Run in non-interactive mode and fail the build if Critical or High issues are found.
python cve_2025_55182_scan.py --ci --fail-on high --static .
dependencies in package.json for vulnerable Next.js (< 14.1.1) and Waku versions. Scans .js/.ts files for "use server", dynamic imports, and Flight protocol markers.Next-Action, Next-Router-State-Tree).report.json with a summary of findings and specific details for remediation.This tool is for educational and authorized security testing purposes only. Ensure you have permission before scanning any target.