The web app is vulnerable to React RCE vulnerabilities CVE-2025-55182
I use a script from github ( https://github.com/Rat5ak/CVE-2025-55182-React2Shell-RCE-POC ) to exploit it