Ross ROSS = Recommend OSS · open-source software intelligence for agents

lachlan2k/React2Shell-CVE-2025-55182-original-poc

Original Proof-of-Concepts for React2Shell CVE-2025-55182 observed · 2026-08-28

github.com/lachlan2k/React2Shell-CVE-2025-55182-original-poc · JavaScript observed · 2026-08-28

Health v2 · maintenance only

41/100

  • Activity 55
  • Release rhythm 35
  • Longevity 19

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 271
  • days_rel: n/a
  • days_push: 271
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1059 stars · 109 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A collection of original proof-of-concept exploits for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components/Next.js. It contains three JavaScript PoCs demonstrating the vulnerability with varying levels of complexity and applicability.

Use cases

  • verify if my Next.js server is vulnerable to CVE-2025-55182
  • study how the React2Shell RCE exploit works
  • reproduce CVE-2025-55182 in a lab environment
  • understand prototype pollution gadget chains in React Server Components
  • test security scanner detection for React2Shell

When to choose

  • you need the original, submitted PoC for CVE-2025-55182 for research or validation
  • you want to understand the exploit mechanics of React2Shell in depth
  • you are testing whether your Next.js/React Server Components deployment is patched

When to avoid

  • you want a general-purpose vulnerability scanner rather than a single-CVE PoC
  • you need a production-safe tool - these are raw exploit scripts
  • you expect documentation or a full writeup, which is not yet included

Facets

application · maturity active

security penetration-testing vulnerability-scanning security web-development developer-tools cli cross-platform exploit proof-of-concept cve-2025-55182 react-server-components rce nextjs react2shell security-research nodejs

1 source

Member repositories

For agents

markdown · JSON · MCP: product_card(name="lachlan2k/React2Shell-CVE-2025-55182-original-poc")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem