discovered 03 Aug 2026
poc-cve-2025-55182
→ View on GitHubThis repository provides a proof-of-concept for CVE-2025-55182, a critical pre-authentication remote code execution vulnerability found in specific versions of React Server Components. The vulnerability enables unauthenticated attackers to execute arbitrary JavaScript code on the server by exploiting unsafe deserialization through prototype chain traversal in the Flight protocol. Notably, the tool facilitates demonstration of the exploit process, requiring a vulnerable React setup and tools like Burp Suite for payload delivery and testing.