discovered 03 Aug 2026
CVE-2025-55182
→ View on GitHubCVE-2025-55182 is a tool designed to exploit a critical prototype pollution vulnerability in React and Next.js Server Actions, allowing for Remote Code Execution (RCE). It features an automated scanning capability via a Nuclei template and a manual exploitation script in Python, enabling the execution of arbitrary commands on vulnerable servers while extracting output effectively from response headers. This tool aims to assist security professionals in assessing the impact of this vulnerability on affected versions of React and Next.js.