Skip to content

React2Shell Scanner

Inspect React Server Components response signals on an authorized target. Results guide manual review and do not confirm a specific vulnerability or patch status.
Start a check
  • Email verification required
  1. 1Input
  2. 2Verify
  3. 3Scan
  4. 4Results
Step 1

Enter Target Details

Provide the URL to scan and your company email for verification. Your email domain must match the target domain to prevent unauthorized scanning.

The URL of the React/Next.js application to scan

Must match the domain being scanned (e.g., @example.com for example.com)

Loading security verification...

Educational Use Only:

This tool is provided for educational and authorized security testing purposes only. You must only scan applications that you own or have explicit written permission to test.

Misuse Warning: Unauthorized scanning of systems you do not own may violate computer fraud laws. Misuse of this tool may be reported to the appropriate authorities.

Your IP Address: ... is being logged for security purposes.

By proceeding, you confirm that you have authorization to scan the target application and consent to Vigilbase storing your information for security logging and future communications.

Introducing the Vigilbase Platform

The cybersecurity operating system.

Connect the security tools you already pay for. Spin up personalised dashboards in minutes, with every log and event auditable and queryable in one place.

one.vigilbase.com/acme.examplePreview · sample data

Acme Security OS

3 sources connected

Ingesting
Cloudflare

Threats mitigated

0

AWS

Root & IAM changes

0

GitHub

Org security changes

0

events | where severity >= medium | last 24h
    Vigil agentWorking
    1. Investigate Credential-stuffing burst against /login
    2. Fix Rate-limit rule deployed at the edge
    3. Verify Attack traffic down 98% in five minutes

    About this vulnerability

    React2Shell (CVE-2025-55182, also tracked by the Next.js advisory CVE-2025-66478) is a critical remote code execution vulnerability in React Server Components. CVE-2025-55183 is a separate, medium-severity source-code exposure issue and does not allow remote code execution.

    View CVE Details

    How this scanner works

    This scanner sends detection requests and inspects RSC response patterns without executing malicious code. These signals need review and do not confirm exploitability. A negative result does not establish that every RSC vulnerability is patched. Verify installed versions against the official React and Next.js advisories.

    What is a React2Shell vulnerability check?

    A React2Shell check looks for remote-code-execution exposure signals on React Server Components / Next.js surfaces. Vigilbase uses safe, non-exploitative probes and requires email verification because the scan is intrusive. Use it only on authorized targets.

    Questions

    React2Shell scanner FAQ

    What is the React2Shell Scanner?

    It is a Vigilbase tool that probes an authorized public URL for React Server Components response signals. Results guide manual assessment; ordinary protocol responses do not confirm a CVE or exploitability.Treat a reported signal as evidence to investigate with the application owner. Confirm the deployed framework and affected version before selecting a remediation, then verify the updated application.Tool access and verification requirementsWebsite Security Check

    Is React2Shell scanning intrusive?

    Yes. Unlike DNS or header checks, React2Shell sends probes to the target application. Only scan systems you own or are explicitly authorized to test. Email verification is required before a scan runs.Receiving a verification code is not proof that you own the target or have permission to test it. Confirm authorization and the intended target before sending application probes.Tool access and verification requirementsHTTP Security Headers Checker

    Can agents run React2Shell autonomously via API?

    No. Intrusive scanners stay browser-gated. Autonomous agents should use the non-intrusive Security Headers or Email Security APIs instead, then point operators to the React2Shell UI when an authorized probe is needed.Run a check through the public APITool access and verification requirements

    Is the React2Shell Scanner free?

    Yes. The public scanner is free after email verification. No Vigilbase account is required to run a check.Free access does not remove the authorization requirement. Results are limited to the probe behavior observed and should not be treated as a complete application security assessment.Compare the public security checksTool access and verification requirements