Skip to content

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

26 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

CVE-2025-55182 Scanner

This repository contains a scanner tool for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC).

⚠️ Disclaimer

This tool is for educational and authorized testing purposes only. Do not use this tool on systems you do not own or have explicit permission to test. The authors are not responsible for any misuse.

Analysis

For a detailed technical analysis, please refer to: https://react2shell.com/

Prerequisites

  • Python 3.x: Required to run the scanner.
  • Dependencies: Install via pip:
    pip3 install requests tqdm

Usage

Basic Scan

Check if a target URL is vulnerable.

python3 CVE-2025-55182.py -u <url>

Scan Multiple Targets

scan a list of hosts from a file (one per line).

python3 CVE-2025-55182.py -l <hosts_file>

Advanced Options

Safe Check

Use side-channel detection (timing/error based) instead of attempting RCE.

python3 CVE-2025-55182.py -u <url> --safe-check

WAF Bypass

Add junk data to bypass WAF content inspection or use specific bypasses.

# Standard WAF bypass (junk data)
python3 CVE-2025-55182.py -u <url> --waf-bypass --waf-bypass-size 128

# Vercel WAF bypass variant
python3 CVE-2025-55182.py -u <url> --vercel-waf-bypass

Output Options

Save results to a file in JSON, CSV, or HTML format.

python3 CVE-2025-55182.py -u <url> -o results.json --format json

All Arguments

Argument Description
-u, --url Single URL/host to check.
-l, --list File containing list of hosts to scan.
-t, --threads Number of concurrent threads (default: 10).
--timeout Request timeout in seconds (default: 10).
-o, --output Output file for results.
--format Output format: json, csv, html.
--safe-check Use safe side-channel detection instead of RCE PoC.
--windows Use Windows PowerShell payload.
--waf-bypass Add junk data to bypass WAF.
--vercel-waf-bypass Use Vercel WAF bypass payload.
--proxy Proxy URL (e.g., http://127.0.0.1:8080).

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages