Proof-of-concept research tool for CVE-2025-55182, a critical unauthenticated RCE in Next.js App Router caused by server-side object injection in React Server Components and Server Actions, including UTF-16LE WAF evasion techniques.
react nextjs waf-bypass react-server-components prototype-pollution server-actions utf-16le remote-code-execution-rce cve-2025-55182
-
Updated
Dec 17, 2025 - Python