Skip to content

Conversation

@Chocapikk
Copy link
Contributor

Hello Metasploit team,

This PR adds Waku framework support to the existing react2shell module (CVE-2025-55182).

Changes:

  • Extended the module to support both Next.js and Waku frameworks
  • Implemented framework-specific payload generation and endpoint handling
  • Added dynamic variant generation for both frameworks
  • Updated documentation with Waku lab setup and usage examples

Testing:

  • Tested with Next.js 15.0.0 on Unix and Windows
  • Tested with Waku 0.12.4-0.26.0-alpha.2-0 on Unix and Windows
  • All payloads verified working (cmd/unix/generic, cmd/unix/reverse_bash, cmd/linux/http/x64/meterpreter/reverse_tcp)

The module maintains backward compatibility with existing Next.js targets while adding Waku support through a modular framework configuration system.

@Chocapikk Chocapikk force-pushed the react2shell-clean branch 2 times, most recently from 87f3165 to 0bce92e Compare December 17, 2025 22:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant