{"repo":"Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478","free":true,"listed":false,"github":"https://github.com/Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478","clone":"git clone https://github.com/Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478.git","description":"A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.","language":"Go","stars":430,"topics":["cve","cve-2025-66478","cve-scanning","nextjs"],"license":null,"category":"security-tools","readme_excerpt":"Next.js RSC RCE Scanner and POC/Exploit Collection (CVE-2025-66478) A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability. This Scanner do not exploit the vulnerability Vulnerability Description https://nextjs.org/blog/CVE-2025-66478 Installation Prerequisites - Go 1.19 or higher - Chrome/Chromium browser (go-rod will download automatically) Build Usage Common Chrome Binary Paths Click to expand paths Linux: - Ubuntu/Debian: /usr/bin/google-chrome or /usr/bin/chromium-browser - CentOS/RHEL: /usr/bin/google-chrome-stable or /usr/bin/chromium - Flatpak: /var/lib/flatpak/exports/bin/com.google.Chrome macOS: - /Applications/Google Chrome.app/Contents/MacOS/Google Chrome - /Applications/Chromium.app/Contents/MacOS/Chromium Windows: - C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe - C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe How It Works 1. Uses go-rod to launch Chrome browser 2. Creates Page Pool to manage concurrency 3. Visits target URL and waits for page load 4. Executes JavaScript window.next.version to get version information 5. Parses version number and determines based on vulnerability scope 6. Outputs scan results Setting Up Vulnerable Environment Install Vulnerable Version Using create-next-app Pop Calculator Click to expand payload 🚨 Runtime Memory Shell 🚨 setup memshell at first Click to expand payload then request to the memshell endpoint to execute a com","default_branch":null,"files":null,"tree":[],"storefront":"/r/Malayke","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}