Documentation
README
Crown Jewel Targets
RCE is the highest-paying class in bug bounty, and the 24-month meta has shifted decisively toward five asset types. All CVEs below are verified against NVD.
1. Modern JS framework deserialization (CVSS 10.0). React Server Components / React Server Functions / Next.js App Router. CVE-2025-55182 (CVSS 10.0, Meta Bug Bounty, Vercel WAF-bypass program on H1, exploited in the wild within 24 hours of disclosure) is the defining 2025-2026 RCE. Every Next.js >=14.3.0-canary.77 / >=15.x / >=16.x deployment running unpatched RSC is a one-request RCE target. Vercel maintains a separate H1 program paying low five-figure bounties for WAF bypasses against this CVE. Hunt this first on any modern JS stack.
This is the opening of the README. Read the full README on GitHub.