webhard

ReactOOPS

hackthebox

Task: exploit a Next.js 16.0.6 application with React Server Components. Solution: use the React2Shell vulnerability (CVE-2025-55182) to achieve pre-auth RCE via prototype chain traversal in the Flight protocol, exfiltrating command output through the X-Action-Redirect header.

$ ls tags/ techniques/
react2shellprototype_chain_traversalflight_protocol_exploitation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]