All verified exploits

CVE-2025-55182 React2Shell RCE

Deterministic critical React CISA KEV Added cve-verified-cve-2025-55182

Executes a harmless math operation through React Server Components prototype chain traversal, proving unauthenticated remote code execution. Includes WAF bypass variants.

Is your app exploitable through CVE-2025-55182?

Scan your domain free