{"adoption": {"forks": 199, "observed_at": "2026-08-28T04:04:42.990728+00:00", "stars": 1431}, "canonical_url": "https://ross.abutalabs.com/products/cve-2025-55182", "card": {"archived": false, "artifact_type": "learning-resource", "description": "Explanation and full RCE PoC for CVE-2025-55182", "domain": ["security", "web-development", "developer-tools"], "enriched": true, "function": ["security", "penetration-testing", "serialization"], "health_score": 54, "homepage": null, "language": "Python", "license": null, "license_family": "other", "maturity": "active", "member_repos": ["msanft/CVE-2025-55182"], "name": "msanft/CVE-2025-55182", "platform": ["python", "cross-platform"], "pushed_at": "2025-12-08T13:51:04+00:00", "repo": "msanft/CVE-2025-55182", "stars": 1431, "tags": ["cve-2025-55182", "rce", "proof-of-concept", "react-server-functions", "nextjs", "prototype-pollution", "vulnerability-research", "exploit", "exploitation"], "topics": [], "urls": [], "use_cases": ["reproduce CVE-2025-55182 remote code execution", "test whether a Next.js app is vulnerable to React Server Function RCE", "learn how React Flight Protocol deserialization can be abused", "study prototype chain traversal attacks in server functions", "craft malicious multipart payloads for React Server Functions", "understand thenable-based exploitation gadgets", "security research on React and Next.js deserialization flaws"], "what_it_is": "A Python proof-of-concept and technical writeup for CVE-2025-55182, a remote code execution vulnerability in React Server Functions (as used by Next.js) caused by insecure prototype references during Flight Protocol deserialization. It explains the vulnerability mechanics and demonstrates full RCE exploitation.", "when_to_avoid": ["you need a general-purpose security scanner rather than a single-CVE PoC", "you want production-ready tooling or maintained exploit frameworks", "you expect official support or a license (the repo has none)", "your target is not running vulnerable React/Next.js Server Functions"], "when_to_choose": ["you need a working PoC to verify or demonstrate CVE-2025-55182", "you are researching React Server Functions or Flight Protocol security", "you are a defender validating patches against this RCE", "you want a detailed technical explanation of the vulnerability"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/cve-2025-55182", "repo": "msanft/CVE-2025-55182", "role": "main", "score": 41}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:42.990728+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:37:08.036638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "3c06085188fa4e808a28bcc94ca29f73914f43692abdbb1dcc2a4e393f812ba5", "fetched_at": "2026-08-28T04:04:42.990728+00:00", "kind": "readme", "missing": false, "url": "https://github.com/msanft/CVE-2025-55182"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 56, "longevity": 19, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 272, "days_push": 268, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 41, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}