React2Shell Scanner
- Email verification required
- 1Input
- 2Verify
- 3Scan
- 4Results
Enter Target Details
Introducing the Vigilbase Platform
The cybersecurity operating system.
Connect the security tools you already pay for. Spin up personalised dashboards in minutes, with every log and event auditable and queryable in one place.
Acme Security OS
events | where severity >= medium | last 24h- Investigate Credential-stuffing burst against /login
- Fix Rate-limit rule deployed at the edge
- Verify Attack traffic down 98% in five minutes
About this vulnerability
React2Shell (CVE-2025-55182, also tracked by the Next.js advisory CVE-2025-66478) is a critical remote code execution vulnerability in React Server Components. CVE-2025-55183 is a separate, medium-severity source-code exposure issue and does not allow remote code execution.
View CVE DetailsHow this scanner works
This scanner sends detection requests and inspects RSC response patterns without executing malicious code. These signals need review and do not confirm exploitability. A negative result does not establish that every RSC vulnerability is patched. Verify installed versions against the official React and Next.js advisories.
What is a React2Shell vulnerability check?
A React2Shell check looks for remote-code-execution exposure signals on React Server Components / Next.js surfaces. Vigilbase uses safe, non-exploitative probes and requires email verification because the scan is intrusive. Use it only on authorized targets.