Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
React2shell-CVE-2025-55182-checker — Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints to identify affected versions in web infrastructure. | Kitploit
Ferramentas/GitHubGitHub/oways/react2shell-cve-2025-55182-checker
Scanners de VulnerabilidadesAnálise de VulnerabilidadesAnálise de CódigoSegurança WebDevSecOpsSegurança da Cadeia de Suprimentos
GitHuboways/react2shell-cve-2025-55182-checker

React2shell-CVE-2025-55182-checker

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints to identify affected versions in web infrastructure.

Ver Repositório
219há 10 mesesAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

CVE-2025-55182 Ferramenta de Detecção React2Shell

Ferramentas de detecção para encontrar Componentes de Servidor React vulneráveis em sua infraestrutura.

Início Rápido

# Install dependencies
pip3 install requests

# Version detection (passive, safe for production)
python3 checker.py -u https://your-app.com

O Que Está Vulnerável

React Server Components:

  • react-server-dom-webpack 19.0.0 - 19.2.0
  • react-server-dom-turbopack 19.0.0 - 19.2.0

Next.js:

  • 15.0.0 - 15.0.4 (inclui React vulnerável)
  • 14.x e 13.5+ (se o React 19 for instalado manualmente)

Corrigido em:

  • React 19.2.1+
  • Next.js 15.0.5+

Ferramentas

checker.py

Detecção passiva de versão. Seguro para executar em produção sem disparar alertas.

# Single target
python3 checker.py -u https://app.example.com

# Multiple targets
python3 checker.py -l targets.txt -o results.json

# Verbose mode
python3 checker.py -u https://app.example.com -v

Verifica strings de versão em package.json, bundles JavaScript, cabeçalhos HTTP e endpoints de API.

Template do Nuclei

Se você usa Nuclei:

# Version detection
nuclei -t CVE-2025-55182-react2shell.yaml -u https://app.example.com
nuclei -t CVE-2025-55182-react2shell.yaml -l targets.txt

Correção

Atualize para as versões corrigidas:

npm update react-server-dom-webpack@latest
npm update next@latest

Verifique a correção:

npm list react-server-dom-webpack next

Demo

Notas

A ferramenta de detecção de versão é segura para produção e não disparará alertas de segurança. Use-a para descoberta inicial e monitoramento contínuo.

Referências

  • Aviso de Segurança do React
  • PR de Correção do React
  • CVE-2025-55182
Baixar ferramenta