Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
check-react-rce-cve-2025-55182 — Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects | Kitploit
Tools/GitHubGitHub/zihxs/check-react-rce-cve-2025-55182
Static AnalysisVulnerability ScannersCode AnalysisWeb SecurityDevSecOpsSupply Chain Security
GitHubzihxs/check-react-rce-cve-2025-55182

check-react-rce-cve-2025-55182

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
6109 months agoNot yet reviewed
Share

React RCE Vulnerability Scanner (CVE-2025-55182)

A comprehensive security scanning tool to detect CVE-2025-55182 and CVE-2025-66478 vulnerabilities in React and Next.js projects using React Server Components (RSC).

CVSS Score Node.js License

🚨 Overview

This tool scans your project for vulnerable versions of React, Next.js, and related RSC packages that are susceptible to Remote Code Execution (RCE) attacks. The vulnerability allows unauthenticated attackers to execute arbitrary code on your server.

⚠️ Critical Alert: As of December 2025, approximately 39% of cloud environments contain instances of Next.js or React with vulnerable versions. Immediate action is required if you're using React Server Components.

✨ Features

  • 🔍 Automatic Package Detection - Scans node_modules for vulnerable package versions
  • 📁 Project Structure Analysis - Detects App Router vs Pages Router usage
  • 🔎 Server Actions Scanner - Finds "use server" directives in your codebase
  • 🛠️ RSC Framework Detection - Identifies RSC-enabled frameworks (Remix, Waku, RedwoodJS, etc.)
  • 📊 Risk Assessment - Provides clear risk conclusions (CRITICAL/MEDIUM/SAFE)
  • 💡 Remediation Guidance - Suggests exact commands to patch vulnerabilities

📦 Packages Scanned

PackageDescription
reactCore React library
nextNext.js framework
react-server-dom-webpackRSC Webpack integration
react-server-dom-parcelRSC Parcel integration
react-server-dom-turbopackRSC Turbopack integration

🚀 Quick Start

Prerequisites

  • Node.js 16 or higher
  • npm or yarn

Installation

  1. Clone this repository or download check.js:
git clone https://github.com/yourusername/check-react-rce-cve-2025-55182.git
  1. Navigate to your React/Next.js project directory:
cd /path/to/your/project
  1. Run the scanner:
node /path/to/check.js

Alternative: Direct Usage

You can also copy check.js directly into your project and run:

node check.js

📋 Sample Output

===========================================================================
             REACT RCE VULNERABILITY SCANNER (CVE-2025-55182)
===========================================================================

Scanning installed packages...
Starting Deep Codebase Scanning...

===========================================================================
                              AUDIT REPORT
===========================================================================

[CVE-2025-55182] React Vulnerability
---------------------------------------------------------------------------
react                          : 19.0.0       VULNERABLE (React 19.0.0 < 19.0.1)
react-server-dom-webpack       : 19.0.0       VULNERABLE (19.0.0 < 19.0.1)

[CVE-2025-66478] Next.js Vulnerability
---------------------------------------------------------------------------
next                           : 15.0.3       VULNERABLE (v15.0.x < 15.0.5)

[Project Analysis]
---------------------------------------------------------------------------
Router Type                    : App Router (RSC-enabled)
Server Actions Usage           : Detected (5 files)

===========================================================================
RISK CONCLUSION: CRITICAL (CVSS 10.0 - Remote Code Execution)
===========================================================================

⚠ ACTION REQUIRED:
Your project uses React Server Components with vulnerable packages.
This vulnerability allows unauthenticated remote code execution.

Vulnerable packages: react, next, react-server-dom-webpack

Run the following commands to patch:
> npm install react@latest react-dom@latest
> npm install next@latest
> npm update react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack

📖 Understanding the Results

Risk Levels

LevelDescription
🔴 CRITICALVulnerable packages detected + RSC features in use. Immediate action required.
🟡 MEDIUMVulnerable packages detected, but RSC not actively detected. Update recommended.
🟢 SAFENo vulnerable packages or using versions before RSC support.

Status Indicators

StatusMeaning
VULNERABLEPackage version is affected by the CVE
SAFEPackage is updated to a patched version
SAFE_CLASSICPackage version predates RSC (not affected)
NOT INSTALLEDPackage not found in project
UNKNOWNUnable to determine version status

🔧 Patched Versions

React (CVE-2025-55182)

BranchVulnerable VersionsPatched Version
React 19.0.x19.0.0≥ 19.0.1
React 19.1.x19.1.0, 19.1.1≥ 19.1.2
React 19.2.x19.2.0≥ 19.2.1
React 18.x and earlier—Not affected (no RSC support)

Next.js (CVE-2025-66478)

BranchPatched Version
Next.js 16.0.x≥ 16.0.7
Next.js 15.5.x≥ 15.5.7
Next.js 15.4.x≥ 15.4.8
Next.js 15.3.x≥ 15.3.6
Next.js 15.2.x≥ 15.2.6
Next.js 15.1.x≥ 15.1.9
Next.js 15.0.x≥ 15.0.5
Next.js 14.3.0-canary.77+⚠️ Vulnerable (canary with Flight Protocol)
Next.js 14.x (stable)Not affected
Next.js 13.xNot affected

Not Affected

The following configurations are NOT affected by these vulnerabilities:

  • Next.js 13.x and earlier
  • Next.js 14.x stable releases
  • Applications using only the Pages Router
  • Applications running on Edge Runtime
  • React 18.x and earlier (no RSC support)

🛡️ About the Vulnerabilities

CVE-2025-55182 (React)

Severity: CRITICAL (CVSS 10.0)

Affected Packages:

  • react-server-dom-webpack
  • react-server-dom-parcel
  • react-server-dom-turbopack

Vulnerability Type: Insecure Deserialization

Description: A critical Remote Code Execution (RCE) vulnerability exists in the react-server package, which is integral to React Server Components (RSC). The flaw stems from an insecure deserialization vulnerability within the RSC "Flight" protocol.

The vulnerability allows an unauthenticated attacker to achieve remote code execution on the server by sending a specially crafted HTTP request to any Server Function endpoint. Even applications that do not explicitly implement React Server Function endpoints may be vulnerable if they support React Server Components, as the vulnerability affects default configurations.

Attack Vector:

  • Attacker sends a specially crafted HTTP request to the server
  • The React Flight protocol processes and deserializes RSC payloads in an unsafe manner
  • Malicious input triggers arbitrary code execution on the server
  • Proof-of-concepts have shown near-100% reliability against default configurations

Impact:

  • Full server compromise
  • Data exfiltration
  • Access to environment variables and secrets
  • Malware installation
  • Lateral movement within infrastructure

References:

  • CVE-2025-55182 Official Record
  • React Security Bulletin (December 3, 2025)

CVE-2025-66478 (Next.js)

Severity: CRITICAL (CVSS 10.0)

Affected Package: next

Vulnerability Type: Insecure Deserialization (inherited from React RSC)

Description: A critical Remote Code Execution vulnerability in Next.js affects applications using the App Router with React Server Components. This vulnerability is the downstream manifestation of CVE-2025-55182, as Next.js inherits the flaw through its implementation of the React Flight protocol.

Download Tool