Ross ROSS = Recommend OSS · open-source software intelligence for agents

msanft/CVE-2025-55182 resource

Explanation and full RCE PoC for CVE-2025-55182 observed · 2026-08-28

github.com/msanft/CVE-2025-55182 · Python observed · 2026-08-28

Health v2 · maintenance only

41/100

  • Activity 56
  • Release rhythm 35
  • Longevity 19

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 272
  • days_rel: n/a
  • days_push: 268
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1431 stars · 199 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Python proof-of-concept and technical writeup for CVE-2025-55182, a remote code execution vulnerability in React Server Functions (as used by Next.js) caused by insecure prototype references during Flight Protocol deserialization. It explains the vulnerability mechanics and demonstrates full RCE exploitation.

Use cases

  • reproduce CVE-2025-55182 remote code execution
  • test whether a Next.js app is vulnerable to React Server Function RCE
  • learn how React Flight Protocol deserialization can be abused
  • study prototype chain traversal attacks in server functions
  • craft malicious multipart payloads for React Server Functions
  • understand thenable-based exploitation gadgets
  • security research on React and Next.js deserialization flaws

When to choose

  • you need a working PoC to verify or demonstrate CVE-2025-55182
  • you are researching React Server Functions or Flight Protocol security
  • you are a defender validating patches against this RCE
  • you want a detailed technical explanation of the vulnerability

When to avoid

  • you need a general-purpose security scanner rather than a single-CVE PoC
  • you want production-ready tooling or maintained exploit frameworks
  • you expect official support or a license (the repo has none)
  • your target is not running vulnerable React/Next.js Server Functions

Facets

learning-resource · maturity active

security penetration-testing serialization security web-development developer-tools python cross-platform cve-2025-55182 rce proof-of-concept react-server-functions nextjs prototype-pollution vulnerability-research exploit exploitation

1 source

Member repositories

RepositoryRoleHealth v2
msanft/CVE-2025-55182main41

For agents

markdown · JSON · MCP: product_card(name="msanft/CVE-2025-55182")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem