Skip to content

Critical Remote Code Execution Confirmed on https://ghostpipe.dev CVE-2025-55182 #14

Description

@rawhack3r

Hello Security Team,

I am reporting a critical, confirmed Remote Code Execution (RCE) vulnerability identified on https://ghostpipe.dev, related to CVE-2025-55182 affecting applications built on React / Next.js (Node.js runtime).

The attached terminal screenshots, which show step-by-step validation.

Vulnerability Details
CVE: CVE-2025-55182
Severity: Critical
Type: Unauthenticated Remote Code Execution
Affected Stack: React / Next.js (Node.js)
Environment Tested: Production

Impact Summary (As Proven in Attached Screenshots)

Image Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions