
Rileva la vulnerabilità RCE CVE-2025-55182 (React2Shell) in React Server Components. Scanner rapido e accurato con zero falsi positivi.
RCE con CVSS 10.0 nei React Server Components. La tua app React 19 è vulnerabile?
Scanner rapido e accurato per CVE-2025-55182 (React2Shell) - una vulnerabilità critica di esecuzione remota di codice sfruttata attivamente in ambienti reali. Zero falsi positivi grazie al rilevamento intelligente dei Server Components.
React2Shell è una vulnerabilità di gravità massima (CVSS 10.0) nei React Server Components che consente l'esecuzione remota di codice senza autenticazione. Gli attaccanti possono sfruttarla tramite richieste HTTP appositamente create verso gli endpoint delle Server Function.
Fatti chiave:
⚠️ Nota critica: Solo React 19.x è vulnerabile. React 18.x e versioni precedenti NON sono interessati.
# Option A: Node.js scanner (recommended - cross-platform, no dependencies)
npx react2shell-scanner /path/to/your/project
# Option B: Direct download and run
curl -sSL https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js > scan.js
node scan.js /path/to/your/project
# Option C: Clone and run
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
node scan.js /path/to/your/project
Risultati in pochi secondi: 🚨 Vulnerabile | ⚠️ Avvisi | ✅ Sicuro
Questo strumento esegue un rilevamento intelligente delle vulnerabilità:
'use server'| Proprietà | Valore |
|---|---|
| CVE ID | CVE-2025-55182 |
| Nome | React2Shell |
| Punteggio CVSS | 10.0 (CRITICO) |
| Vettore CVSS | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Vettore di attacco | Rete |
| Autenticazione | Non richiesta |
| Impatto | Compromissione completa del sistema |
React:
19.0.0, 19.1.0, 19.1.1, 19.2.0Pacchetti React Server DOM:
react-server-dom-webpack 19.0.0 - 19.2.0react-server-dom-parcel 19.0.0 - 19.2.0react-server-dom-turbopack 19.0.0 - 19.2.0Next.js:
14.0.0 a 14.2.3414.3.0-canary.0 a 14.3.0-canary.8715.0.0 a 15.0.615.1.0 a 15.1.815.2.0 a 15.2.515.3.0 a 15.3.515.4.0 a 15.4.715.5.0 a 15.5.616.0.0 a 16.0.9Framework aggiuntivi interessati (secondo l'avviso ufficiale di React):
react-router 7.0.0 - 7.1.3waku 0.21.0 - 0.21.5@parcel/rsc 2.12.0 - 2.13.2@vitejs/plugin-rsc 0.1.0 - 0.2.0rwsdk (Redwood SDK) 0.1.0 - 0.4.0expo 52.0.0 - 52.0.9React: 19.2.1 o successive
Next.js:
14.2.35+, 14.3.0-canary.88+15.0.7+, 15.1.9+, 15.2.6+, 15.3.6+, 15.4.8+, 15.5.7+16.0.10+Altri framework:
react-router: 7.1.4+waku: 0.21.6+@parcel/rsc: 2.13.3+@vitejs/plugin-rsc: 0.2.1+rwsdk: 0.4.1+expo: 52.0.10+Scanner Node.js (consigliato):
Scanner Bash:
# Install jq (if using Bash scanner)
# macOS
brew install jq
# Ubuntu/Debian
sudo apt-get install jq
# RHEL/CentOS
sudo yum install jq
Opzione A: Clona (consigliata per gli utenti)
# Clone the repository
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
# Make scripts executable
chmod +x scan.sh scan.js
Opzione B: Fork (consigliata per i contributori)
# Fork on GitHub (click "Fork" button on repository page)
# Then clone your fork
git clone https://github.com/YOUR_USERNAME/react2shell-scanner.git
cd react2shell-scanner
# Make scripts executable
chmod +x scan.sh scan.js
# Add upstream remote to stay updated
git remote add upstream https://github.com/nxgn-kd01/react2shell-scanner.git
Opzione C: Download diretto
# Node.js version (recommended - cross-platform)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js
chmod +x scan.js
# Bash version (Unix/Linux/macOS only)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.sh
chmod +x scan.sh
🔍 Scansione della directory corrente:
# Using Node.js (recommended)
node scan.js
# Using Bash
./scan.sh
📁 Scansione di un progetto specifico:
node scan.js /path/to/project
./scan.sh /path/to/project
🗂️ Scansione ricorsiva (tutte le sottodirectory):
node scan.js -r
./scan.sh -r
Output JSON (per l'automazione):
node scan.js --json
./scan.sh --json
Modalità CI/CD (termina con codice 1 in caso di vulnerabilità):
node scan.js --ci
./scan.sh --ci
Output dettagliato (verbose):
node scan.js -v
./scan.sh -v
Combina le opzioni:
node scan.js /path/to/projects -r --json --ci
./scan.sh /path/to/projects -r --json --ci
| Opzione | Descrizione |
|---|---|
-r, --recursive | Analizza tutte le sottodirectory per i progetti Node.js |
-v, --verbose | Mostra un output dettagliato |
--json | Restituisce i risultati in formato JSON |
--ci | Termina con codice 1 se vengono trovate vulnerabilità (per CI/CD) |
-h, --help | Mostra il messaggio di aiuto |