cve-shield.dev — Web interface for Assetnote's react2shell-scanner
CVE-2025-55182 & CVE-2025-66478
Quick Scan for RCE Vulnerabilities
No CLI install needed. Quickly check your Next.js apps for React Server Components vulnerabilities using Assetnote's detection methodology.
react2shell-scanner (Assetnote)
$python scanner.py -u https://target.com --safe
[*] React2Shell Scanner v1.0.0
[*] Scanning https://target.com...
[*] Testing path: /
[+] Vulnerable! CVE-2025-55182 detected
[*] Response header: X-Action-Redirect: /login?a=11111
This web version implements the same detection logic. For full features, use the original CLI tool.
Live Vulnerability Scanner
5/5scans
Scan Target
Enter URL to scan for RSC vulnerabilities
One URL per line for bulk scanning
Scan Settings
Safe mode: Will detect vulnerability without code execution
10/10
CVSS Score
Critical Severity
100K+
Apps at Risk
Next.js deployments
<1s
Scan Time
Per target
Zero
False Positives
High fidelity detection
How It Works
Same detection methodology as Assetnote's scanner
Safe Check Mode
Detect vulnerabilities using side-channel indicators without executing code on targets.
WAF Bypass
Built-in techniques to bypass WAF content inspection that only analyzes initial request portions.
High Fidelity
Zero false positives with deterministic math operation verification (41×271=11111).
Bulk Scanning
Scan multiple targets at once. Enter one URL per line for batch checks.
Full CLI Available
Need threading, proxies, or advanced features? Use the original Assetnote CLI tool.
Copy Results
Easily copy scan results for reporting, documentation, or further analysis.
For production security, use the original CLI tool.