{"_id":"@amirmalek/fix-react2shell","_rev":"3-30c50342a7d3c0591087203df9402582","name":"@amirmalek/fix-react2shell","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@amirmalek/fix-react2shell","version":"1.0.0","keywords":["react","nextjs","security","cve","cve-2025-55182","react2shell","vulnerability","scanner","fix","upgrade"],"author":{"name":"Amir Malek"},"license":"MIT","_id":"@amirmalek/fix-react2shell@1.0.0","maintainers":[{"name":"amirmalek","email":"ahmalekpour1999@gmail.com"}],"homepage":"https://github.com/amir-malek/react-cve-2025-55182#readme","bugs":{"url":"https://github.com/amir-malek/react-cve-2025-55182/issues"},"bin":{"fix-react2shell":"fix-react2shell.js"},"dist":{"shasum":"c518ea63a993211788910eb0752d314369d32f2d","tarball":"https://registry.npmjs.org/@amirmalek/fix-react2shell/-/fix-react2shell-1.0.0.tgz","fileCount":3,"integrity":"sha512-posSBQBn1RLjlWbYHdWbzarqZ0++EV2nL8lFprv0QMJ5ILl6JEtyKHm/9Ss7+dSivrfdNvUoQFfyqsGPu5TWKg==","signatures":[{"sig":"MEUCIAXZ1EeY4ssHxza/dd3lnAAs24FdmZvLRoLE3V6AkAM8AiEAn1nijdh1/aTjp2NyHTTFUXpwcWu/GQnB6WrWWOJ8u1U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16490},"main":"fix-react2shell.js","engines":{"node":">=14.0.0"},"gitHead":"5761273c88f07b338cfdc8fddb12b0ae0a473267","scripts":{"start":"node fix-react2shell.js"},"_npmUser":{"name":"amirmalek","email":"ahmalekpour1999@gmail.com"},"repository":{"url":"git+https://github.com/amir-malek/react-cve-2025-55182.git","type":"git"},"_npmVersion":"11.4.2","description":"CLI tool to detect and fix CVE-2025-55182 (React2Shell) vulnerability in React Server Components and Next.js","directories":{},"_nodeVersion":"24.4.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/fix-react2shell_1.0.0_1765301251462_0.9450948048843166","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@amirmalek/fix-react2shell","version":"1.0.1","keywords":["react","nextjs","security","cve","cve-2025-55182","react2shell","vulnerability","scanner","fix","upgrade"],"author":{"name":"Amir Malek"},"license":"MIT","_id":"@amirmalek/fix-react2shell@1.0.1","maintainers":[{"name":"amirmalek","email":"ahmalekpour1999@gmail.com"}],"homepage":"https://github.com/amir-malek/react-cve-2025-55182#readme","bugs":{"url":"https://github.com/amir-malek/react-cve-2025-55182/issues"},"bin":{"fix-react2shell":"fix-react2shell.js"},"dist":{"shasum":"d163a86c034fd1e0dc4cd721804a38e041642f6a","tarball":"https://registry.npmjs.org/@amirmalek/fix-react2shell/-/fix-react2shell-1.0.1.tgz","fileCount":3,"integrity":"sha512-fFiX52Ws+GPQuWjsVwKsEQf1b4VmzqOQ+UCb9MH1tFvraWUnWsP46qsHvij9FlBd0rg9qqpLAUoNr92vpUMfBg==","signatures":[{"sig":"MEQCIAEzLH4k5mk6pI5FIr5F1BzSAyYHVxmbgECBKKVrmOT8AiAu4h/iYSLZzvb2MtVntAqxdirmJB0a6UdqSBbPa2jg8Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16595},"main":"fix-react2shell.js","engines":{"node":">=14.0.0"},"gitHead":"cd6c8dfb08d302c417308e021a90fee9886ad573","scripts":{"start":"node fix-react2shell.js"},"_npmUser":{"name":"amirmalek","email":"ahmalekpour1999@gmail.com"},"repository":{"url":"git+https://github.com/amir-malek/react-cve-2025-55182.git","type":"git"},"_npmVersion":"11.4.2","description":"CLI tool to detect and fix CVE-2025-55182 (React2Shell) vulnerability in React Server Components and Next.js","directories":{},"_nodeVersion":"24.4.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/fix-react2shell_1.0.1_1765313581760_0.17481659757646573","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@amirmalek/fix-react2shell","version":"1.0.2","description":"CLI tool to detect and fix CVE-2025-55182 (React2Shell) vulnerability in React Server Components and Next.js","main":"fix-react2shell.js","bin":{"fix-react2shell":"fix-react2shell.js"},"scripts":{"start":"node fix-react2shell.js"},"keywords":["react","nextjs","security","cve","cve-2025-55182","react2shell","vulnerability","scanner","fix","upgrade"],"author":{"name":"Amir Malek"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/amir-malek/react-cve-2025-55182.git"},"bugs":{"url":"https://github.com/amir-malek/react-cve-2025-55182/issues"},"homepage":"https://github.com/amir-malek/react-cve-2025-55182#readme","engines":{"node":">=14.0.0"},"_id":"@amirmalek/fix-react2shell@1.0.2","gitHead":"b3ecdd16d6e643d2b2730425ac3a241e6e66fc2d","_nodeVersion":"24.4.1","_npmVersion":"11.4.2","dist":{"integrity":"sha512-zTWdR6Ei2Qy0gvsvbqLUrtwTMyRIbmV1TALgtTgWwCGul7ezdDpVARJg4vMAePvEybHJZW0X5yQprh+SGR319Q==","shasum":"01b0027c918e0c56257ab2544f057ccb28694e00","tarball":"https://registry.npmjs.org/@amirmalek/fix-react2shell/-/fix-react2shell-1.0.2.tgz","fileCount":4,"unpackedSize":18494,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD6WcfUNUUhXQBI8TjziHGIu6MFGUxvHsAnCg3BHrfCLwIhAIWl4LWFHzhRBwEsx20AFAc83McEEr/9aOPDPdEocZ35"}]},"_npmUser":{"name":"amirmalek","email":"ahmalekpour1999@gmail.com"},"directories":{},"maintainers":[{"name":"amirmalek","email":"ahmalekpour1999@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/fix-react2shell_1.0.2_1765358698611_0.8134831011877586"},"_hasShrinkwrap":false}},"time":{"created":"2025-12-09T17:27:31.382Z","modified":"2025-12-10T09:24:59.001Z","1.0.0":"2025-12-09T17:27:31.640Z","1.0.1":"2025-12-09T20:53:01.959Z","1.0.2":"2025-12-10T09:24:58.807Z"},"bugs":{"url":"https://github.com/amir-malek/react-cve-2025-55182/issues"},"author":{"name":"Amir Malek"},"license":"MIT","homepage":"https://github.com/amir-malek/react-cve-2025-55182#readme","keywords":["react","nextjs","security","cve","cve-2025-55182","react2shell","vulnerability","scanner","fix","upgrade"],"repository":{"type":"git","url":"git+https://github.com/amir-malek/react-cve-2025-55182.git"},"description":"CLI tool to detect and fix CVE-2025-55182 (React2Shell) vulnerability in React Server Components and Next.js","maintainers":[{"name":"amirmalek","email":"ahmalekpour1999@gmail.com"}],"readme":"# fix-react2shell\n\nA CLI tool to detect and fix the critical **CVE-2025-55182** (React2Shell) vulnerability in React Server Components and Next.js applications.\n\n## The Vulnerability\n\n**CVE-2025-55182** is a critical (CVSS 10.0) unauthenticated remote code execution vulnerability affecting:\n\n- **React Server DOM packages** (versions 19.0.0, 19.1.0, 19.1.1, 19.2.0)\n- **Next.js** (versions 14.3.0-canary.77 through unpatched 15.x and 16.x)\n\nThe vulnerability is an unsafe deserialization flaw in the React Server Components Flight protocol. Exploitation requires only a crafted HTTP request, and public exploit code is available.\n\n**There is no workaround** — upgrading to a patched version is required.\n\n### More Information\n\n- [React Official Advisory](https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components)\n- [Next.js Security Advisory](https://nextjs.org/blog/CVE-2025-66478)\n- [Vercel Summary](https://vercel.com/changelog/cve-2025-55182)\n\n## Installation\n\n### Option 1: Run directly with npx\n\n```bash\nnpx @amirmalek/fix-react2shell\n```\n\n### Option 2: Clone this repository\n\n```bash\ngit clone https://github.com/amir-malek/react-cve-2025-55182.git\ncd react-cve-2025-55182\nnode fix-react2shell.js\n```\n\n### Option 3: Download the script\n\n```bash\ncurl -O https://raw.githubusercontent.com/amir-malek/react-cve-2025-55182/main/fix-react2shell.js\nnode fix-react2shell.js\n```\n\n## Usage\n\nNavigate to your React/Next.js project directory and run:\n\n```bash\n# Dry-run mode (default) - shows what would be upgraded\nnpx @amirmalek/fix-react2shell\n\n# Actually perform the upgrades\nnpx @amirmalek/fix-react2shell --fix\n\n# Show detailed version information\nnpx @amirmalek/fix-react2shell --verbose\n\n# Show help\nnpx @amirmalek/fix-react2shell --help\n```\n\n## Example Output\n\n```\n╔══════════════════════════════════════════════════════════════╗\n║        CVE-2025-55182 (React2Shell) Vulnerability Scanner    ║\n╚══════════════════════════════════════════════════════════════╝\n\nPackage manager: yarn\nProject: my-nextjs-app\n\n⚠ Found 1 vulnerable package(s):\n\n  ✗ next\n    Current: 15.3.5 → Safe: 15.3.7\n\n────────────────────────────────────────────────────────────\nDRY RUN MODE - No changes made.\nRun with --fix to upgrade packages.\n\nCommand that would be run:\n  yarn add next@15.3.7\n```\n\n## Features\n\n- **Smart Detection** — Only flags actually vulnerable versions, not all React 19 projects\n- **Multi-Package Manager Support** — Automatically detects and uses npm, yarn, or pnpm\n- **Safe by Default** — Runs in dry-run mode unless `--fix` is explicitly passed\n- **Zero Dependencies** — Uses only Node.js built-in modules\n- **Portable** — Works in any project directory\n\n## Vulnerable Versions\n\n### React Server DOM Packages\n\n| Package | Vulnerable | Safe |\n|---------|-----------|------|\n| `react-server-dom-webpack` | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |\n| `react-server-dom-parcel` | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |\n| `react-server-dom-turbopack` | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |\n\n### Next.js\n\n| Branch | Safe Version |\n|--------|-------------|\n| 15.0.x | 15.0.5 |\n| 15.1.x | 15.1.9 |\n| 15.2.x | 15.2.6 |\n| 15.3.x | 15.3.6 |\n| 15.4.x | 15.4.8 |\n| 15.5.x | 15.5.7 |\n| 16.0.x | 16.0.7 |\n\n## After Upgrading\n\nOnce you have patched your versions and redeployed your application, it is **strongly recommended** to:\n\n1. **Rotate all application secrets** (API keys, database credentials, JWT secrets, etc.)\n2. **Review application logs** for any signs of prior exploitation\n3. **Audit your infrastructure** if you suspect compromise\n\n## License\n\nMIT\n\n## Contributing\n\nIssues and pull requests are welcome at [github.com/amir-malek/react-cve-2025-55182](https://github.com/amir-malek/react-cve-2025-55182).\n","readmeFilename":"README.md"}