Sign inSign up

caovanthanh203/react2shell-scanner

By caovanthanh203

•Updated 10 months ago

Scan RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) powered by assetnote/react2shell-scanner

Image
Networking
Security
Developer tools
1

486

caovanthanh203/react2shell-scanner repository overview

⁠react2shell-scanner

Image:

caovanthanh203/react2shell-scanner:latest

Original git: https://github.com/assetnote/react2shell-scanner⁠

A command-line tool for detecting CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server Components.

For technical details on the vulnerability and detection methodology, see our blog post: https://slcyber.io/research-center/high-fidelity-detection-mechanism-for-rsc-next-js-rce-cve-2025-55182-cve-2025-66478⁠

⁠Usage with Docker

The easiest way to run the scanner is with a pre-built Docker image, which avoids the need to install Python or other dependencies.

⁠Option 1: Run with docker-compose

Create docker-compose.yml file

version: '3.8'

services:
  scanner:
    build: .
    image: caovanthanh203/react2shell-scanner:latest
    volumes:
      - .:/app
docker-compose run --rm scanner -u https://example.com

⁠Option 2: Run quickly without docker-compose

docker run --rm -it -v "$(pwd):/app" caovanthanh203/react2shell-scanner:latest -u https://example.com

⁠Pull image for later

#pull image
docker pull caovanthanh203/react2shell-scanner:latest

⁠How It Works

By default, the scanner sends a crafted multipart POST request containing an RCE proof-of-concept payload that executes a deterministic math operation (41*271 = 11111). Vulnerable hosts return the result in the X-Action-Redirect response header as /login?a=11111.

The scanner tests the root path (/) by default. Use --path or --path-file to test custom paths. If not vulnerable, it follows same-host redirects (e.g., / to /en/) and tests the redirect destination. Cross-origin redirects are not followed.

⁠Safe Check Mode

The --safe-check flag uses an alternative detection method that relies on side-channel indicators (500 status code with specific error digest) without executing code on the target. Use this mode when RCE execution is not desired.

⁠WAF Bypass

The --waf-bypass flag prepends random junk data to the multipart request body. This can help evade WAF content inspection that only analyzes the first portion of request bodies. The default size is 128KB, configurable via --waf-bypass-size. When WAF bypass is enabled, the timeout is automatically increased to 20 seconds (unless explicitly set).

⁠Vercel WAF Bypass

The --vercel-waf-bypass flag uses an alternative payload variant specifically designed to bypass Vercel WAF protections. This uses a different multipart structure with an additional form field.

⁠Windows Mode

The --windows flag switches the payload from Unix shell (echo $((41*271))) to PowerShell (powershell -c "41*271") for targets running on Windows.

⁠Options

-u, --url         Single URL to check
-l, --list        File containing hosts (one per line)
-t, --threads     Number of concurrent threads (default: 10)
--timeout         Request timeout in seconds (default: 10)
-o, --output      Output file for results (JSON)
--all-results     Save all results, not just vulnerable hosts
-k, --insecure    Disable SSL certificate verification
-H, --header      Custom header (can be used multiple times)
-v, --verbose     Show response details for vulnerable hosts
-q, --quiet       Only output vulnerable hosts
--no-color        Disable colored output
--safe-check      Use safe side-channel detection instead of RCE PoC
--windows         Use Windows PowerShell payload instead of Unix shell
--waf-bypass      Add junk data to bypass WAF content inspection
--waf-bypass-size Size of junk data in KB (default: 128)
--path            Custom path to test (can be used multiple times)
--path-file       File containing paths to test (one per line)

⁠Credits

The RCE PoC was originally disclosed by @maple3142⁠ -- we are incredibly grateful for their work in publishing a working PoC.

This tooling originally was built out as a safe way to detect the RCE. This functionality is still available via --safe-check, the "safe detection" mode.

⁠Output

Results are printed to the terminal. When using -o, vulnerable hosts are saved to a JSON file containing the full HTTP request and response for verification.

Tag summary

Content type

Image

Digest

sha256:8eb4b9ee0…

Size

46.3 MB

Last updated

10 months ago

docker pull caovanthanh203/react2shell-scanner