Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2025-55182-scanner — Passive vulnerability scanner for CVE-2025-55182 and CVE-2025-66478, detecting unauthenticated RCE in React Server Components via framework fingerprinting, version analysis, and RSC endpoint probing. | Kitploit
Tools/GitHubGitHub/xkillbit/cve-2025-55182-scanner
Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubxkillbit/cve-2025-55182-scanner

cve-2025-55182-scanner

Passive vulnerability scanner for CVE-2025-55182 and CVE-2025-66478, detecting unauthenticated RCE in React Server Components via framework fingerprinting, version analysis, and RSC endpoint probing.

View Repository
41210 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182 / CVE-2025-66478 Vulnerability Scanner

React Server Components Flight Protocol Remote Code Execution Detection Tool

CVSS Score Disclosure Date License


Executive Summary

This scanner identifies systems potentially vulnerable to CVE-2025-55182 (React) and CVE-2025-66478 (Next.js), critical unauthenticated remote code execution vulnerabilities in the React Server Components (RSC) "Flight" protocol.

Key Risk Factors:

  • CVSS 10.0 - Maximum severity
  • Unauthenticated - No login required
  • Remote - Exploitable over the network
  • Default configurations affected
  • Near 100% exploitation reliability reported

Table of Contents

  1. Vulnerability Overview
  2. How the Scanner Works
  3. Installation
  4. Usage
  5. Understanding Results
  6. Confidence Levels
  7. Limitations
  8. Recommendations
  9. References

Vulnerability Overview

What is CVE-2025-55182?

A critical insecure deserialization vulnerability in React's Server Components implementation. The RSC "Flight" protocol fails to properly validate the structure and types of incoming payloads, allowing attackers to inject malicious data that influences server-side execution.

Affected Components

PackageVulnerable VersionsPatched Versions
react-server-dom-webpack19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1
react-server-dom-parcel19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1
react-server-dom-turbopack19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1
Next.js14.3.0-canary.77+, 15.x, 16.0.0-16.0.615.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7

Affected Frameworks

  • Next.js (App Router)
  • React Router (RSC preview)
  • Vite RSC plugin
  • Parcel RSC plugin
  • RedwoodJS (RedwoodSDK)
  • Waku

Attack Vector

Attacker → Crafted HTTP POST → RSC Endpoint → Deserialization → RCE

The attack requires only a specially crafted HTTP request to any Server Function endpoint. No authentication is needed, and default configurations are vulnerable.


How the Scanner Works

Detection Methodology

The scanner uses passive fingerprinting and protocol probing to identify potentially vulnerable systems. It does NOT attempt exploitation.

┌─────────────────────────────────────────────────────────────────┐
│                     DETECTION PIPELINE                          │
├─────────────────────────────────────────────────────────────────┤
│                                                                 │
│  1. Framework Detection                                         │
│     ├── HTTP Headers (X-Powered-By: Next.js)                   │
│     ├── Page Source (__NEXT_DATA__, react artifacts)           │
│     └── Build Manifests                                         │
│                                                                 │
│  2. Version Fingerprinting                                      │
│     ├── Embedded version strings in JS bundles                 │
│     ├── Package version patterns                                │
│     └── Build manifest analysis                                 │
│                                                                 │
│  3. RSC Endpoint Discovery                                      │
│     ├── Send RSC headers (RSC: 1, Accept: text/x-component)    │
│     ├── Analyze response Content-Type                          │
│     └── Detect Flight protocol markers in response             │
│                                                                 │
│  4. Server Actions Probing                                      │
│     ├── POST request with minimal Flight payload               │
│     ├── Check for deserialization processing                   │
│     └── Identify action endpoints                              │
│                                                                 │
│  5. Vulnerability Assessment                                    │
│     ├── Correlate version with known vulnerable ranges         │
│     ├── Weight RSC endpoint presence                           │
│     └── Generate confidence-scored verdict                     │
│                                                                 │
└─────────────────────────────────────────────────────────────────┘

Technical Detection Methods

1. Framework Detection

IndicatorDetection MethodConfidence
X-Powered-By: Next.jsHTTP header inspectionHigh
__NEXT_DATA__ script tagHTML source parsingHigh
/_next/ asset pathsHTML source parsingMedium
React hydration markersHTML source parsingMedium

2. RSC Protocol Detection

The Flight protocol uses a specific wire format:

0:["$","div",null,{"children":"Hello"}]
1:["$","$L1",null,{}]
2:{"name":"ServerComponent"}

The scanner looks for:

  • text/x-component Content-Type
  • Chunk format: {number}:{payload}
  • Reference markers: $, $L, $F, $@, $undefined

3. Version Fingerprinting

Searches for version patterns in:

  • JavaScript bundles (/_next/static/chunks/)
  • Build manifests
  • Inline scripts
  • Package references ([email protected])

Installation

Requirements

  • Python 3.8+
  • requests library

Setup

# Clone or download the scanner files
# Install dependencies
pip install -r requirements.txt

# Verify installation
python3 cve-2025-55182-scanner.py --help

Usage

Basic Scan

# Single target
python3 cve-2025-55182-scanner.py -t https://example.com

# With verbose output
python3 cve-2025-55182-scanner.py -t https://example.com -v

Batch Scanning

# Create targets file (one URL per line)
echo "https://app1.example.com" > targets.txt
echo "https://app2.example.com" >> targets.txt

# Scan all targets
python3 cve-2025-55182-scanner.py -f targets.txt -o results.json

Advanced Options

python3 cve-2025-55182-scanner.py -t https://example.com \
    --timeout 15 \
    --threads 10 \
    --user-agent "SecurityAudit/1.0" \
    -v \
    -o scan_results.json

Command Line Options

OptionDescriptionDefault
-t, --targetSingle target URL-
-f, --fileFile with target list-
-o, --outputJSON output file-
-v, --verboseShow detailed evidenceFalse
--timeoutRequest timeout (seconds)10
--threadsConcurrent threads5
--verify-sslVerify SSL certificatesFalse
--user-agentCustom User-AgentMozilla/5.0...
--no-bannerSuppress bannerFalse

Using the RSC Analyzer Module

For deeper protocol analysis:

python3 rsc_analyzer.py https://example.com 2>/dev/null

This provides detailed Flight protocol analysis and component enumeration.


Understanding Results

Status Categories

StatusMeaningAction Required
🔴 VULNERABLEConfirmed vulnerable version detectedImmediate patching
🔴 LIKELY_VULNERABLEReact 19.x with RSC, version in vulnerable rangeUrgent patching
🟡 POTENTIALLY_VULNERABLERSC endpoints found, version unknownInvestigate & patch
🟢 NOT_VULNERABLEPatched version confirmedMonitor for updates
🔵 UNKNOWNCould not determine statusManual verification needed
⚪ ERRORScan failedRetry or manual check

Sample Output

Download Tool