{"repo":"kavienanj/CVE-2025-55182","free":true,"listed":false,"github":"https://github.com/kavienanj/CVE-2025-55182","clone":"git clone https://github.com/kavienanj/CVE-2025-55182.git","description":"Step-by-step walkthrough of CVE-2025-55182 (React2Shell) by tracing React's Flight protocol internals.","language":null,"stars":38,"topics":["cve-2025-55182","nextjs","react2shell","reactjs"],"license":null,"category":"security-tools","readme_excerpt":"React2Shell: CVE-2025-55182 Walkthrough Author: Kavienan J Vulnerability discovered by: lachlan2k, who responsibly disclosed it to the React team. For updates on this vulnerability, visit: react2shell.com Table of Contents 1. Introduction 2. Background 3. Understanding ReactFlightReplyServer.js 4. Crafting the First Payload 5. The Fake Chunk 6. All Under Control 7. The Exploit 8. The Fix --- Introduction CVE-2025-55182 is rated 10.0/10.0 in severity. If you've looked at the public PoCs, you may have noticed that while they show the exploit working, the explanations for why the payload looks the way it does can feel insufficient—which makes perfect sense given how complicated the React Flight Protocol is. Flight, the serialization layer behind React Server Components and Server Actions, is an intricate 1,100+ line state machine, and its behavior isn't intuitive unless you trace the code yourself. The community PoCs demonstrate the vulnerability clearly: - https://github.com/msanft/CVE-2025-55182 - https://github.com/lachlan2k/React2Shell-CVE-2025-55182-original-poc - https://x.com/rauchg/status/1997362942929440937 …but when you try to answer \"Why does this work?\", you quickly find yourself spelunking deep into React internals that were never meant to be read line by line. Note: Many PoCs incorrectly attribute the fix to changes in requireModule . As we'll see in The Fix, the exploit payload never reaches that function—the actual vulnerable code resides entirely in ReactFlightR","default_branch":null,"files":null,"tree":[],"storefront":"/r/kavienanj","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/kavienanj/CVE-2025-55182/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}