# assetnote/react2shell-scanner

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Repository: https://github.com/assetnote/react2shell-scanner
Canonical: https://ross.abutalabs.com/products/react2shell-scanner
Language: Python
License Family: other
Last push: 2025-12-07T04:16:46+00:00

## Health v2 (maintenance only)
Score: 41/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 56, release rhythm 35, longevity 19
- inputs: {"age_days": 272, "days_push": 269, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2459, forks 271 (observed 2026-08-28T04:06:53.369092+00:00)

## What it is
A Python command-line scanner that detects RCE vulnerabilities CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server Components. It sends crafted multipart POST payloads with a deterministic math proof-of-concept and offers safe side-channel detection, WAF bypass, and Windows target modes.

## Use cases
- scan next.js sites for cve-2025-55182 rce
- check if my react server components app is vulnerable
- bulk scan a list of hosts for react2shell
- detect next.js rce without executing code on target
- bypass waf when scanning for rce vulnerability
- scan windows-hosted next.js for rce

## When to choose
- you need high-fidelity detection of CVE-2025-55182/CVE-2025-66478 in Next.js/RSC apps
- you want a safe side-channel check mode that avoids executing code
- you need bulk scanning with threading, custom headers, and JSON output

## When to avoid
- your stack does not use Next.js or React Server Components
- you need a general-purpose web vulnerability scanner rather than a targeted CVE check
- you are not authorized to test the target hosts

## Facets
- artifact type: cli-tool
- maturity: active
- function: vulnerability-scanning, security, cli
- domain: security, penetration-testing, web-development, developer-tools
- platform: cli, python, cross-platform
- tags: cve-scanner, nextjs, react-server-components, rce-detection, waf-bypass, pentesting

## Member repositories
- assetnote/react2shell-scanner (main) score 41

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:53.369092+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:29:20.891197+00:00, confidence not recorded.
  - readme: https://github.com/assetnote/react2shell-scanner (fetched 2026-08-28T04:06:53.369092+00:00, sha 4fd2078e336d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
