
Détecte la vulnérabilité RCE CVE-2025-55182 (React2Shell) dans les composants serveur React. Scanner rapide et précis avec zéro faux positif.
RCE CVSS 10.0 dans les React Server Components. Votre application React 19 est-elle vulnérable ?
Scanner rapide et précis pour CVE-2025-55182 (React2Shell) - une vulnérabilité critique d'exécution de code à distance exploitée dans la nature. Zéro faux positif grâce à une détection intelligente des Server Components.
React2Shell est une vulnérabilité de sévérité maximale (CVSS 10.0) dans les React Server Components permettant l'exécution de code à distance sans authentification. Les attaquants peuvent l'exploiter via des requêtes HTTP spécialement conçues envoyées aux points de terminaison des Server Functions.
Points clés :
⚠️ Note critique : Seul React 19.x est vulnérable. React 18.x et versions antérieures ne sont PAS concernés.
# Option A: Node.js scanner (recommended - cross-platform, no dependencies)
npx react2shell-scanner /path/to/your/project
# Option B: Direct download and run
curl -sSL https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js > scan.js
node scan.js /path/to/your/project
# Option C: Clone and run
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
node scan.js /path/to/your/project
Résultats en quelques secondes : 🚨 Vulnérable | ⚠️ Avertissements | ✅ Sûr
Cet outil effectue une détection intelligente des vulnérabilités :
'use server'| Propriété | Valeur |
|---|---|
| ID CVE | CVE-2025-55182 |
| Nom | React2Shell |
| Score CVSS | 10.0 (CRITIQUE) |
| Vecteur CVSS | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Vecteur d'attaque | Réseau |
| Authentification | Aucune requise |
| Impact | Compromission totale du système |
React :
19.0.0, 19.1.0, 19.1.1, 19.2.0Paquets React Server DOM :
react-server-dom-webpack 19.0.0 - 19.2.0react-server-dom-parcel 19.0.0 - 19.2.0react-server-dom-turbopack 19.0.0 - 19.2.0Next.js :
14.0.0 à 14.2.3414.3.0-canary.0 à 14.3.0-canary.8715.0.0 à 15.0.615.1.0 à 15.1.815.2.0 à 15.2.515.3.0 à 15.3.515.4.0 à 15.4.715.5.0 à 15.5.616.0.0 à 16.0.9Autres frameworks affectés (selon l'avis officiel de React) :
react-router 7.0.0 - 7.1.3waku 0.21.0 - 0.21.5@parcel/rsc 2.12.0 - 2.13.2@vitejs/plugin-rsc 0.1.0 - 0.2.0rwsdk (Redwood SDK) 0.1.0 - 0.4.0expo 52.0.0 - 52.0.9React : 19.2.1 ou version ultérieure
Next.js :
14.2.35+, 14.3.0-canary.88+15.0.7+, 15.1.9+, 15.2.6+, 15.3.6+, 15.4.8+, 15.5.7+16.0.10+Autres frameworks :
react-router : 7.1.4+waku : 0.21.6+@parcel/rsc : 2.13.3+@vitejs/plugin-rsc : 0.2.1+rwsdk : 0.4.1+expo : 52.0.10+Scanner Node.js (recommandé) :
Scanner Bash :
# Install jq (if using Bash scanner)
# macOS
brew install jq
# Ubuntu/Debian
sudo apt-get install jq
# RHEL/CentOS
sudo yum install jq
Option A : Cloner (recommandé pour les utilisateurs)
# Clone the repository
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
# Make scripts executable
chmod +x scan.sh scan.js
Option B : Fork (recommandé pour les contributeurs)
# Fork on GitHub (click "Fork" button on repository page)
# Then clone your fork
git clone https://github.com/YOUR_USERNAME/react2shell-scanner.git
cd react2shell-scanner
# Make scripts executable
chmod +x scan.sh scan.js
# Add upstream remote to stay updated
git remote add upstream https://github.com/nxgn-kd01/react2shell-scanner.git
Option C : Téléchargement direct
# Node.js version (recommended - cross-platform)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js
chmod +x scan.js
# Bash version (Unix/Linux/macOS only)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.sh
chmod +x scan.sh
🔍 Analyser le répertoire courant :
# Using Node.js (recommended)
node scan.js
# Using Bash
./scan.sh
📁 Analyser un projet spécifique :
node scan.js /path/to/project
./scan.sh /path/to/project
🗂️ Analyse récursive (tous les sous-répertoires) :
node scan.js -r
./scan.sh -r
Sortie JSON (pour l'automatisation) :
node scan.js --json
./scan.sh --json
Mode CI/CD (se termine avec le code 1 si vulnérable) :
node scan.js --ci
./scan.sh --ci
Sortie détaillée :
node scan.js -v
./scan.sh -v
Combiner les options :
node scan.js /path/to/projects -r --json --ci
./scan.sh /path/to/projects -r --json --ci