
React2Shell-CVE-2025-55182
React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

Educational lab demonstrating CVE-2025-55182: Critical RCE in React Server Components via prototype pollution in the Flight protocol

Proof-of-concept for CVE-2025-55182 (React2Shell): unauthenticated RCE in React Server Components / Next.js via Flight protocol deserialization.

Scanner for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Track and remediate a critical React Server Components (RSC) / Flight protocol…

Cloud native secrets management for developers - never leave your command line for secrets.

Proof-of-concept exploit for CVE-2025-55182, a critical RCE vulnerability in Next.js Server Actions. Exploits insecure deserialization in the React…

CLI scanner that detects likely vulnerable React/Next.js dependencies for CVE-2025-55182 and provides mitigation targets. Supports JSON output and…

Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server…

PoC exploit for CVE-2025-55182, demonstrating remote code execution in React Server Functions via prototype pollution and a crafted Flight Protocol…

Proof-of-concept exploit for CVE-2025-55182, achieving remote code execution in React Server Functions via prototype pollution and crafted Flight…

This repository documents research into deserialization behavior within Next.js React Server Components (RSC) using the Flight protocol. It focuses…

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…