Skip to main content

React2Shell – CVE-2025-55182 Next.js RSC RCE

Project description

CVE-2025-55182 – React2Shell 🔥

React2Shell is a security research tool that exploits
CVE-2025-55182, a Remote Code Execution (RCE) vulnerability in
Next.js React Server Components (RSC).

This tool allows authorized security testers to execute system commands on vulnerable Next.js applications by abusing the RSC action handling and redirect mechanism.


React2Shell Banner

📌 Vulnerability Overview

  • CVE ID: CVE-2025-55182
  • Affected Technology: Next.js (React Server Components)
  • Impact: Remote Code Execution (RCE)
  • Attack Vector: Crafted multipart RSC action request
  • Severity: Critical

🔗 NVD Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-55182


🚀 Features

  • ✅ Reliable RCE exploitation
  • ✅ Clean CLI interface
  • ✅ Colored output with execution results
  • ✅ Minimal dependencies
  • ✅ Easy integration into recon / automation pipelines
  • ✅ Designed for security researchers & red teamers

📦 Installation

pip install CYBERTECHMIND-CVE-2025-55182

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cybertechmind_cve_2025_55182-1.0.0.tar.gz (4.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

cybertechmind_cve_2025_55182-1.0.0-py3-none-any.whl (5.4 kB view details)

Uploaded Python 3

File details

Details for the file cybertechmind_cve_2025_55182-1.0.0.tar.gz.

File metadata

File hashes

Hashes for cybertechmind_cve_2025_55182-1.0.0.tar.gz
Algorithm Hash digest
SHA256 1e5ef9d6049d0ad31eda19113da3c6e85c2b1636708b049b4df06b39de2808e9
MD5 57d49e0286adf3c987c7057ee38dc7e0
BLAKE2b-256 ef102208edd5e27f2860b5f4e61158ffeefcb38a132c5a9ceb4dace19ccb5181

See more details on using hashes here.

File details

Details for the file cybertechmind_cve_2025_55182-1.0.0-py3-none-any.whl.

File metadata

File hashes

Hashes for cybertechmind_cve_2025_55182-1.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 32ec93860c4d6c546e0206301c91ef0a069d517fb5a5cf480347b136348f2e60
MD5 e3b44a27602e266103a7473f00ebd773
BLAKE2b-256 90180aff56a0d2b4e4149e5b53227857ffac283e238d76639855c6ac3a2b4c78

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page