PoC-in-GitHub/2025/CVE-2025-66478.json
2025-12-18 03:45:19 +09:00

717 lines
No EOL
25 KiB
JSON

[
{
"id": 1109394752,
"name": "next-cve-2025-66478",
"full_name": "abtonc\/next-cve-2025-66478",
"owner": {
"login": "abtonc",
"id": 62848063,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/62848063?v=4",
"html_url": "https:\/\/github.com\/abtonc",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/abtonc\/next-cve-2025-66478",
"description": null,
"fork": false,
"created_at": "2025-12-03T18:38:53Z",
"updated_at": "2025-12-08T15:59:02Z",
"pushed_at": "2025-12-08T15:58:59Z",
"stargazers_count": 10,
"watchers_count": 10,
"has_discussions": false,
"forks_count": 1,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 1,
"watchers": 10,
"score": 0,
"subscribers_count": 0
},
{
"id": 1109726413,
"name": "CVE-2025-66478-POC",
"full_name": "wangxso\/CVE-2025-66478-POC",
"owner": {
"login": "wangxso",
"id": 35062162,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/35062162?v=4",
"html_url": "https:\/\/github.com\/wangxso",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/wangxso\/CVE-2025-66478-POC",
"description": "CVE-2025-66478 Proof of Concept",
"fork": false,
"created_at": "2025-12-04T07:44:47Z",
"updated_at": "2025-12-17T06:51:50Z",
"pushed_at": "2025-12-17T06:51:47Z",
"stargazers_count": 4,
"watchers_count": 4,
"has_discussions": false,
"forks_count": 1,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 1,
"watchers": 4,
"score": 0,
"subscribers_count": 0
},
{
"id": 1109917013,
"name": "Next.js-RSC-RCE-Scanner-CVE-2025-66478",
"full_name": "Malayke\/Next.js-RSC-RCE-Scanner-CVE-2025-66478",
"owner": {
"login": "Malayke",
"id": 4935500,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/4935500?v=4",
"html_url": "https:\/\/github.com\/Malayke",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/Malayke\/Next.js-RSC-RCE-Scanner-CVE-2025-66478",
"description": "A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.",
"fork": false,
"created_at": "2025-12-04T13:13:33Z",
"updated_at": "2025-12-17T17:48:11Z",
"pushed_at": "2025-12-16T03:18:16Z",
"stargazers_count": 360,
"watchers_count": 360,
"has_discussions": false,
"forks_count": 76,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [
"cve",
"cve-2025-66478",
"cve-scanning",
"nextjs"
],
"visibility": "public",
"forks": 76,
"watchers": 360,
"score": 0,
"subscribers_count": 1
},
{
"id": 1110188862,
"name": "check-cve-2025-66478",
"full_name": "mattcbarrett\/check-cve-2025-66478",
"owner": {
"login": "mattcbarrett",
"id": 20583142,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/20583142?v=4",
"html_url": "https:\/\/github.com\/mattcbarrett",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/mattcbarrett\/check-cve-2025-66478",
"description": "Checks if your NextJS server is vulnerable to CVE-2025-66478",
"fork": false,
"created_at": "2025-12-04T20:50:51Z",
"updated_at": "2025-12-05T16:11:47Z",
"pushed_at": "2025-12-05T16:11:44Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1110894422,
"name": "react2shell-ultimate",
"full_name": "hackersatyamrastogi\/react2shell-ultimate",
"owner": {
"login": "hackersatyamrastogi",
"id": 47441267,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/47441267?v=4",
"html_url": "https:\/\/github.com\/hackersatyamrastogi",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/hackersatyamrastogi\/react2shell-ultimate",
"description": "React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local scanning.",
"fork": false,
"created_at": "2025-12-05T22:20:14Z",
"updated_at": "2025-12-17T17:41:28Z",
"pushed_at": "2025-12-10T09:35:17Z",
"stargazers_count": 117,
"watchers_count": 117,
"has_discussions": false,
"forks_count": 25,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [
"bug-bounty",
"cve-2025-55182",
"cve-2025-66478",
"cybersecurity",
"nextjs",
"penetration-testing",
"rce",
"react-server-components",
"security-scanner",
"vulnerability-scanner"
],
"visibility": "public",
"forks": 25,
"watchers": 117,
"score": 0,
"subscribers_count": 2
},
{
"id": 1110970432,
"name": "fix-react2shell-next",
"full_name": "vercel-labs\/fix-react2shell-next",
"owner": {
"login": "vercel-labs",
"id": 108547162,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/108547162?v=4",
"html_url": "https:\/\/github.com\/vercel-labs",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/vercel-labs\/fix-react2shell-next",
"description": "One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js \/ React RSC app.",
"fork": false,
"created_at": "2025-12-06T02:41:12Z",
"updated_at": "2025-12-17T13:08:33Z",
"pushed_at": "2025-12-12T03:03:50Z",
"stargazers_count": 354,
"watchers_count": 354,
"has_discussions": false,
"forks_count": 51,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 51,
"watchers": 354,
"score": 0,
"subscribers_count": 2
},
{
"id": 1111055409,
"name": "CVE-2025-66478-Exploit-Poc",
"full_name": "namest504\/CVE-2025-66478-Exploit-Poc",
"owner": {
"login": "namest504",
"id": 61047602,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/61047602?v=4",
"html_url": "https:\/\/github.com\/namest504",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/namest504\/CVE-2025-66478-Exploit-Poc",
"description": null,
"fork": false,
"created_at": "2025-12-06T07:12:45Z",
"updated_at": "2025-12-13T21:28:58Z",
"pushed_at": "2025-12-06T08:25:51Z",
"stargazers_count": 1,
"watchers_count": 1,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 1,
"score": 0,
"subscribers_count": 0
},
{
"id": 1111439739,
"name": "CVE-2025-66478-kinda-waf",
"full_name": "aiexz\/CVE-2025-66478-kinda-waf",
"owner": {
"login": "aiexz",
"id": 42418433,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/42418433?v=4",
"html_url": "https:\/\/github.com\/aiexz",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/aiexz\/CVE-2025-66478-kinda-waf",
"description": "Let's help websites stay safe until they are properly patched!",
"fork": false,
"created_at": "2025-12-06T23:52:07Z",
"updated_at": "2025-12-07T00:06:55Z",
"pushed_at": "2025-12-07T00:06:52Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1111449339,
"name": "CVE-2025-66478",
"full_name": "Rhyru9\/CVE-2025-66478",
"owner": {
"login": "Rhyru9",
"id": 164749781,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/164749781?v=4",
"html_url": "https:\/\/github.com\/Rhyru9",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/Rhyru9\/CVE-2025-66478",
"description": null,
"fork": false,
"created_at": "2025-12-07T00:32:06Z",
"updated_at": "2025-12-07T02:42:12Z",
"pushed_at": "2025-12-07T02:42:09Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1111479834,
"name": "CVE-2025-66478-github-patcher",
"full_name": "Jibaru\/CVE-2025-66478-github-patcher",
"owner": {
"login": "Jibaru",
"id": 54339832,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/54339832?v=4",
"html_url": "https:\/\/github.com\/Jibaru",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/Jibaru\/CVE-2025-66478-github-patcher",
"description": null,
"fork": false,
"created_at": "2025-12-07T02:39:22Z",
"updated_at": "2025-12-07T02:40:05Z",
"pushed_at": "2025-12-07T02:40:02Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1112024960,
"name": "CVE-2025-66478",
"full_name": "ExpTechTW\/CVE-2025-66478",
"owner": {
"login": "ExpTechTW",
"id": 91672109,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/91672109?v=4",
"html_url": "https:\/\/github.com\/ExpTechTW",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/ExpTechTW\/CVE-2025-66478",
"description": null,
"fork": false,
"created_at": "2025-12-08T03:30:20Z",
"updated_at": "2025-12-10T02:39:40Z",
"pushed_at": "2025-12-08T03:45:33Z",
"stargazers_count": 2,
"watchers_count": 2,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 2,
"score": 0,
"subscribers_count": 0
},
{
"id": 1112082516,
"name": "cve-2025-66478",
"full_name": "abhirajranjan\/cve-2025-66478",
"owner": {
"login": "abhirajranjan",
"id": 61920199,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/61920199?v=4",
"html_url": "https:\/\/github.com\/abhirajranjan",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/abhirajranjan\/cve-2025-66478",
"description": null,
"fork": false,
"created_at": "2025-12-08T05:59:27Z",
"updated_at": "2025-12-08T08:54:03Z",
"pushed_at": "2025-12-08T08:53:59Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1112335315,
"name": "cve-2025-66478_rce_vulnerable",
"full_name": "Letalandroid\/cve-2025-66478_rce_vulnerable",
"owner": {
"login": "Letalandroid",
"id": 78810527,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/78810527?v=4",
"html_url": "https:\/\/github.com\/Letalandroid",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/Letalandroid\/cve-2025-66478_rce_vulnerable",
"description": "IMPORTANTE: Proyecto de Next JS VULNERABLE creado solo para fines educativos, de pruebas y explotación, NO SE RECOMIENDA INSTALACIÓN EN PRODUCCION, SÓLO PARA ÁMBITO LOCAL O ENTORNO CONTROLADO",
"fork": false,
"created_at": "2025-12-08T13:34:49Z",
"updated_at": "2025-12-08T14:46:30Z",
"pushed_at": "2025-12-08T14:46:26Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1112600385,
"name": "react2shell-honeypot",
"full_name": "strainxx\/react2shell-honeypot",
"owner": {
"login": "strainxx",
"id": 100953533,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/100953533?v=4",
"html_url": "https:\/\/github.com\/strainxx",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/strainxx\/react2shell-honeypot",
"description": "My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)",
"fork": false,
"created_at": "2025-12-08T21:11:00Z",
"updated_at": "2025-12-11T21:02:26Z",
"pushed_at": "2025-12-08T21:12:04Z",
"stargazers_count": 2,
"watchers_count": 2,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [
"cve",
"cve-2025-66478",
"honeypot",
"nextjs",
"react",
"react2shell"
],
"visibility": "public",
"forks": 0,
"watchers": 2,
"score": 0,
"subscribers_count": 1
},
{
"id": 1114163525,
"name": "Next.js-RSC-RCE-Scanner-CVE-2025-66478",
"full_name": "changgun-lee\/Next.js-RSC-RCE-Scanner-CVE-2025-66478",
"owner": {
"login": "changgun-lee",
"id": 155412589,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/155412589?v=4",
"html_url": "https:\/\/github.com\/changgun-lee",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/changgun-lee\/Next.js-RSC-RCE-Scanner-CVE-2025-66478",
"description": null,
"fork": false,
"created_at": "2025-12-11T01:49:52Z",
"updated_at": "2025-12-11T02:00:58Z",
"pushed_at": "2025-12-11T02:00:54Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1114638183,
"name": "nexts-cve-2025-66478-exploit",
"full_name": "Code42Cate\/nexts-cve-2025-66478-exploit",
"owner": {
"login": "Code42Cate",
"id": 26679776,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/26679776?v=4",
"html_url": "https:\/\/github.com\/Code42Cate",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/Code42Cate\/nexts-cve-2025-66478-exploit",
"description": null,
"fork": false,
"created_at": "2025-12-11T16:57:40Z",
"updated_at": "2025-12-11T17:09:29Z",
"pushed_at": "2025-12-11T17:09:25Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1115242689,
"name": "poc-cve-next",
"full_name": "viperh\/poc-cve-next",
"owner": {
"login": "viperh",
"id": 65122445,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/65122445?v=4",
"html_url": "https:\/\/github.com\/viperh",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/viperh\/poc-cve-next",
"description": "PoC for Next.js RCE Vulnerability CVE-2025-66478",
"fork": false,
"created_at": "2025-12-12T14:54:11Z",
"updated_at": "2025-12-12T14:57:39Z",
"pushed_at": "2025-12-12T14:57:35Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1115456948,
"name": "rsc-security-auditor",
"full_name": "abdozkaya\/rsc-security-auditor",
"owner": {
"login": "abdozkaya",
"id": 74666618,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/74666618?v=4",
"html_url": "https:\/\/github.com\/abdozkaya",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/abdozkaya\/rsc-security-auditor",
"description": "🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix commands. 100% Client-side.",
"fork": false,
"created_at": "2025-12-12T22:37:06Z",
"updated_at": "2025-12-14T20:24:38Z",
"pushed_at": "2025-12-13T12:04:58Z",
"stargazers_count": 4,
"watchers_count": 4,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [
"cve-scanning",
"nextjs",
"react",
"rsc",
"vulnerability-scanners"
],
"visibility": "public",
"forks": 0,
"watchers": 4,
"score": 0,
"subscribers_count": 0
},
{
"id": 1116374163,
"name": "-vercel-prod.yml-application-is-vulnerable-to-CVE-2025-66478.",
"full_name": "DavionGowie\/-vercel-prod.yml-application-is-vulnerable-to-CVE-2025-66478.",
"owner": {
"login": "DavionGowie",
"id": 202416665,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/202416665?v=4",
"html_url": "https:\/\/github.com\/DavionGowie",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/DavionGowie\/-vercel-prod.yml-application-is-vulnerable-to-CVE-2025-66478.",
"description": "bug bounty",
"fork": false,
"created_at": "2025-12-14T18:25:36Z",
"updated_at": "2025-12-14T18:25:40Z",
"pushed_at": "2025-12-14T18:25:37Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1116377116,
"name": "-vercel-application-is-vulnerable-to-CVE-2025-66478.",
"full_name": "DavionGowie\/-vercel-application-is-vulnerable-to-CVE-2025-66478.",
"owner": {
"login": "DavionGowie",
"id": 202416665,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/202416665?v=4",
"html_url": "https:\/\/github.com\/DavionGowie",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/DavionGowie\/-vercel-application-is-vulnerable-to-CVE-2025-66478.",
"description": "bug bounty",
"fork": false,
"created_at": "2025-12-14T18:32:44Z",
"updated_at": "2025-12-14T18:32:47Z",
"pushed_at": "2025-12-14T18:32:44Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1116529032,
"name": "CVE-2025-66478-Exploit-PoC",
"full_name": "zhixiangyao\/CVE-2025-66478-Exploit-PoC",
"owner": {
"login": "zhixiangyao",
"id": 49728521,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/49728521?v=4",
"html_url": "https:\/\/github.com\/zhixiangyao",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/zhixiangyao\/CVE-2025-66478-Exploit-PoC",
"description": "Proof-of-concept exploit demo for CVE-2025-66478 using Node.js",
"fork": false,
"created_at": "2025-12-15T02:27:02Z",
"updated_at": "2025-12-16T08:41:00Z",
"pushed_at": "2025-12-16T08:40:57Z",
"stargazers_count": 0,
"watchers_count": 0,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [
"cve-2025-66478",
"nextjs",
"nodejs"
],
"visibility": "public",
"forks": 0,
"watchers": 0,
"score": 0,
"subscribers_count": 0
},
{
"id": 1118223480,
"name": "nextjs-cve-2025-66478-ctf",
"full_name": "mio-qwq\/nextjs-cve-2025-66478-ctf",
"owner": {
"login": "mio-qwq",
"id": 234856096,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/234856096?v=4",
"html_url": "https:\/\/github.com\/mio-qwq",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/mio-qwq\/nextjs-cve-2025-66478-ctf",
"description": null,
"fork": false,
"created_at": "2025-12-17T12:45:06Z",
"updated_at": "2025-12-17T12:53:54Z",
"pushed_at": "2025-12-17T12:49:23Z",
"stargazers_count": 1,
"watchers_count": 1,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 1,
"score": 0,
"subscribers_count": 0
}
]