{"repo":"sammwyy/R2SAE","free":true,"listed":false,"github":"https://github.com/sammwyy/R2SAE","clone":"git clone https://github.com/sammwyy/R2SAE.git","description":"React2Shell Auto Exploit: A CLI tool to exploit prototype pollution vulnerabilities (RCE) in React Server Actions","language":"Python","stars":63,"topics":["cli","exploit","exploit-development","exploit-kit","next","nextjs","rce","rce-exploit","rce-scanner","rce-testing"],"license":null,"category":"cli-tools","readme_excerpt":"R2SAE - React2Shell Auto-Exploit A CLI tool to exploit prototype pollution vulnerabilities in React Server Actions, enabling remote command execution (RCE) on vulnerable servers. ⚠️ Warning This tool is for educational purposes and authorized security testing only. Unauthorized use of this tool against systems without permission is illegal and strictly prohibited. 📋 Requirements - Python 3.6 or higher - requests = 2.31.0 🔧 Installation 1. Clone the repository: 2. Install dependencies: Or install directly: 📖 Usage R2SAE uses a subcommand-based interface. The main commands are: - exec - Execute commands on target host(s) - shell - Interactive shell mode - scan - Scan host(s) for vulnerability Exec Command Execute a specific command on one or more target servers: Examples: Shell Command Start an interactive shell to execute multiple commands on one or more hosts: Example: In interactive mode: - Type commands and press Enter to execute them on all hosts - Each result shows the host that generated it: (host) output - Type exit , quit or q to exit - Use Ctrl+C to interrupt Scan Command Scan one or more hosts for vulnerability detection: Examples: Scan Methods: - Passive (default) : Evaluates a mathematical expression ( 1337 + 42 ) without executing system commands. Safer and less intrusive. - Active ( --active ) : Executes the id command to verify vulnerability. More accurate but more intrusive. Global Options 📝 Usage examples Example 1: Execute command on single host Output: E","default_branch":null,"files":null,"tree":[],"storefront":"/r/sammwyy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sammwyy/R2SAE/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}