A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.
-
Updated
Dec 16, 2025 - Go
A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.
React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local scanning.
Docker poc lab for CVE-2025-55182 / CVE-2025-66478 (React2Shell) detection and exploitation
🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478
This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell.
Nuclei template for detecting react2shell (CVE-2025-55182 & CVE-2025-66478)
Precision-Based Detection of RSC/Next.js Remote Code Execution Vulnerabilities (CVE-2025-55182, CVE-2025-66478)
A Chrome extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications
A bash scanner for detecting CVE-2025-55182 vulnerability in Next.js applications
A critical vulnerability in React Server Components affecting React 19 (CVE-2025-55182) and frameworks that use it like Next.js (CVE-2025-66478).
Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE). Includes detailed vulnerability analysis, exploitation techniques, and team learning materials.
My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)
Torito React2Shell Scanner & Exploit Tool (CVE-2025-55182 / 66478)
PoC for React2Shell (CVE-2025-55182)
CVE-2025-55182 & CVE-2025-66478 Detection Tool for Next.js RSC RCE
CVE-2025-55182 + CVE-2025-66478 - Next.js/React Server Components Remote Code Execution
High-performance Go implementation for detecting React Server Components RCE vulnerabilities (CVE-2025-55182 & CVE-2025-66478).
Proof-of-concept exploit demo for CVE-2025-66478 using Node.js
A CLI tool that exploits vulnerabilities in React Server Components and Server Actions (CVE-2025-55182, CVE-2025-66478) to achieve remote code execution (RCE) on vulnerable servers.
This is a fast, asynchronous Python tool that fingerprints domains for likely Next.js App Router / React Server Components (RSC) infrastructure. (I made it to find the applications possibly vulnerable to CVE-2025-55182 and CVE-2025-66478)
Add a description, image, and links to the cve-2025-66478 topic page so that developers can more easily learn about it.
To associate your repository with the cve-2025-66478 topic, visit your repo's landing page and select "manage topics."