React2shell - RSC Sentinel από Muhammad Uwais
A Firefox extension for detecting React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478) in web applications.
Μεταδεδομένα επέκτασης
Στιγμιότυπα
Σχετικά με την επέκταση
Overview
RSC Sentinel is a Firefox browser extension for security researchers and educators who want to observe React Server Components (RSC) and Next.js App Router indicators while browsing. It focuses on passive detection by default, highlighting potential signals without altering site behavior. For authorized assessments, it also offers optional manual tools for active probing and controlled command execution initiated by the user.
Features
How Detection Works (High-Level)
RSC Sentinel evaluates a combination of runtime indicators, HTTP response headers, and response content patterns that are commonly associated with RSC and App Router behavior. Results are presented as signals and should be interpreted as indicators rather than definitive proof of vulnerability.
RSC Sentinel is a Firefox browser extension for security researchers and educators who want to observe React Server Components (RSC) and Next.js App Router indicators while browsing. It focuses on passive detection by default, highlighting potential signals without altering site behavior. For authorized assessments, it also offers optional manual tools for active probing and controlled command execution initiated by the user.
Features
- Passive Detection: Automatically watches for high-level RSC and App Router indicators during normal browsing.
- Active Probing: Allows a user-initiated fingerprint request to gather additional signals in a controlled manner.
- Manual Command Execution: Provides a manual, user-driven execution workflow intended strictly for authorized testing.
How Detection Works (High-Level)
RSC Sentinel evaluates a combination of runtime indicators, HTTP response headers, and response content patterns that are commonly associated with RSC and App Router behavior. Results are presented as signals and should be interpreted as indicators rather than definitive proof of vulnerability.
Βαθμολογήθηκε με 5 από έναν αξιολογητή
Δικαιώματα και δεδομένα
Απαιτούμενα δικαιώματα:
- Έχει πρόσβαση στα δεδομένα σας για κάθε ιστότοπο
Προαιρετικά δικαιώματα:
- Έχει πρόσβαση στα δεδομένα σας για κάθε ιστότοπο
Συλλογή δεδομένων:
- Ο δημιουργός δηλώνει ότι αυτή η επέκταση δεν απαιτεί συλλογή δεδομένων.
Περισσότερες πληροφορίες
- Έκδοση
- 1.1
- Μέγεθος
- 166,75 KB
- Τελευταία ενημέρωση
- 10 ώρες πριν (13 Φεβ 2026)
- Σχετικές κατηγορίες
- Ιστορικό εκδόσεων
- Προσθήκη σε συλλογή