
react2shell-scanner
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Detect and bypass web application firewalls and protection systems

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

IP obfuscator made to make a malicious ip a bit cuter

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Disrupt WAF by abusing SSL/TLS Ciphers

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

CVE-2025-55182复现环境及RCE回显poc

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

Proof-of-concept exploit for CVE-2025-55182, demonstrating unauthenticated RCE in Next.js App Router via server-side object injection in React Server…

Scans for CVE-2025-55182, a critical RCE in React Server Components, with safe-check mode, WAF bypass, and multi-target scanning.

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…