
cve-2025-55182-lab
Docker-based lab reproducing CVE-2025-55182 (React2Shell), an unauthenticated RCE in React Server Components Flight Protocol, with PoC exploit and…

Docker-based lab reproducing CVE-2025-55182 (React2Shell), an unauthenticated RCE in React Server Components Flight Protocol, with PoC exploit and…

Python PoC exploiting CVE-2026-12944, an SSRF in Langflow 1.10.0 via urllib in custom components, with authenticated read and fetch capabilities.

Proof-of-concept exploit for CVE-2026-13181 affecting Telerik web components, demonstrating remote code execution via crafted requests.

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Wiki-style research notebook for Zyxel WAX650S firmware emulation and vulnerability analysis

Proof-of-concept exploit for CVE-2026-23869, a denial-of-service vulnerability in React Server Components allowing unauthenticated CPU exhaustion via…

Automated exploit tool for CVE-2026-23869, a remote DoS in React Server Components. Includes PoC, Nuclei template, and scanning scripts for detection…

Proof-of-concept demonstrating a URL parsing bypass in Python's urllib.parse (CVE-2023-24329) that allows bypassing blocklists by prepending spaces.

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

Technical analysis of CVE-2025-55182 (React2Shell), covering vulnerability mechanics, root cause, controlled PoC testing, impact, and mitigation…

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

Security advisories for CVE-2021-43716/43717/43718 (Epson EH-TW5350)

WebKit+Kernel exploit chain for all PS Vita firmwares

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)


Proof-of-concept for a stored XSS vulnerability in i-doit Pro 25 and below, demonstrating payload injection via multiple parameters and components…

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints…

Shell-based vulnerability scanner for CVE-2025-55182, a critical RCE in Next.js React Server Components. Designed for authorized penetration testing,…