React2shell - RSC Sentinel 作成者: Muhammad Uwais
A Firefox extension for detecting React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478) in web applications.
拡張機能メタデータ
スクリーンショット
この拡張機能について
Overview
RSC Sentinel is a Firefox browser extension for security researchers and educators who want to observe React Server Components (RSC) and Next.js App Router indicators while browsing. It focuses on passive detection by default, highlighting potential signals without altering site behavior. For authorized assessments, it also offers optional manual tools for active probing and controlled command execution initiated by the user.
Features
How Detection Works (High-Level)
RSC Sentinel evaluates a combination of runtime indicators, HTTP response headers, and response content patterns that are commonly associated with RSC and App Router behavior. Results are presented as signals and should be interpreted as indicators rather than definitive proof of vulnerability.
RSC Sentinel is a Firefox browser extension for security researchers and educators who want to observe React Server Components (RSC) and Next.js App Router indicators while browsing. It focuses on passive detection by default, highlighting potential signals without altering site behavior. For authorized assessments, it also offers optional manual tools for active probing and controlled command execution initiated by the user.
Features
- Passive Detection: Automatically watches for high-level RSC and App Router indicators during normal browsing.
- Active Probing: Allows a user-initiated fingerprint request to gather additional signals in a controlled manner.
- Manual Command Execution: Provides a manual, user-driven execution workflow intended strictly for authorized testing.
How Detection Works (High-Level)
RSC Sentinel evaluates a combination of runtime indicators, HTTP response headers, and response content patterns that are commonly associated with RSC and App Router behavior. Results are presented as signals and should be interpreted as indicators rather than definitive proof of vulnerability.
1 人のレビュー担当者が 5 と評価しました
権限とデータ
必要な権限:
- すべてのウェブサイトの保存されたデータへのアクセス
任意の許可設定:
- すべてのウェブサイトの保存されたデータへのアクセス
データ収集:
- 開発者によると、この拡張機能はデータ収集を必要としません。
詳しい情報
- バージョン
- 1.1
- サイズ
- 166.75 KB
- 最終更新日
- 15時間前 (2026年2月13日)
- 関連カテゴリー
- バージョン履歴
- コレクションへ追加