
Multi-Technik-Schwachstellendetektor für CVE-2025-55182 in React/Next.js-Anwendungen. Testet Gadget-Ketten, RCE-Payloads und WAF-Bypass-Varianten, um verwundbare Server Actions-Endpunkte zu identifizieren.
Ein umfassendes Erkennungstool für CVE-2025-55182 in React/Next.js-Anwendungen mit mehreren Erkennungstechniken.
NUR FÜR AUTORISIERTE SICHERHEITSTESTS UND FORSCHUNGSZWECKE
Dieses Tool ist vorgesehen für:
Unbefugter Zugriff auf Computersysteme ist illegal. Holen Sie vor dem Testen immer eine schriftliche Genehmigung ein.
Dieser Detektor testet umfassend, ob eine Zielanwendung mit mehreren Techniken anfällig für CVE-2025-55182 ist:
Das Tool testet Node.js-Gadget-Ketten mit harmlosen Operationen:
1+1)echo test)path)/dev/null)Testvorgänge:
echo test, 1+1)/dev/null)Tut NICHT:
Dieses Tool verwendet uv zur Abhängigkeitsverwaltung und Ausführung.
Keine Installation erforderlich! Einfach klonen und ausführen:
git clone <repository-url>
cd CVE-2025-55182/poc
uv run check http://target.com:3000
Das Tool installiert Abhängigkeiten beim ersten Start automatisch.
uv run check <target_url>
# Test a target with default settings (tests /formaction endpoint)
uv run check http://localhost:3002
# Specify custom endpoint
uv run check http://localhost:3002 --endpoint /api/formaction
# Test multiple targets from a file
uv run check --file targets.txt
# Save vulnerable hosts to file
uv run check --file targets.txt -o vulnerable.txt
# Increase timeout for slow connections
uv run check http://localhost:3002 --timeout 15
# Disable SSL verification (for self-signed certificates)
uv run check http://localhost:3002 --no-ssl-verify
# Quiet mode (minimal output)
uv run check http://localhost:3002 --quiet
usage: uv run check [-h] [-f FILE] [-e ENDPOINT] [-t TIMEOUT]
[--no-ssl-verify] [-q] [-o OUTPUT] [target]
positional arguments:
target Ziel-URL (z.B. http://target.com:3000)
optional arguments:
-h, --help Hilfemeldung anzeigen und beenden
-f, --file FILE Datei mit Ziel-URLs (eine pro Zeile)
-e, --endpoint API-Endpunkt-Pfad (Standard: /formaction)
-t, --timeout Anfrage-Timeout in Sekunden (Standard: 10)
--no-ssl-verify SSL-Zertifikatsprüfung deaktivieren
-q, --quiet Stiller Modus (minimale Ausgabe)
-o, --output OUTPUT Ausgabedatei zum Schreiben verwundbarer Hosts
0 - Ziel ist NICHT verwundbar1 - Ziel IST verwundbar130 - Benutzer unterbrochen (Strg+C)# uv run check http://localhost:3002
======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================
[*] Testing http://localhost:3002/formaction
[*] Testing all detection techniques...
→ Gadget: fs#constructor: ✓ VULNERABLE
→ Gadget: vm#runInThisContext: ✓ VULNERABLE
→ Gadget: child_process#execSync: ✓ VULNERABLE
→ Gadget: module#_load: ✓ VULNERABLE
→ Gadget: fs#readFileSync: ✓ VULNERABLE
→ Gadget: util#promisify: ✗ Not vulnerable
→ Safe Side-Channel Detection: ✗ Not vulnerable
→ RCE PoC (Unix/Linux): ✗ Not vulnerable
→ RCE PoC (Windows): ✗ Not vulnerable
→ RCE with WAF Bypass (Unix/Linux): ✗ Not vulnerable
→ RCE with WAF Bypass (Windows): ✗ Not vulnerable
→ Advanced WAF Bypass (Unix/Linux): ✗ Not vulnerable
======================================================================
DETECTION RESULTS
======================================================================
Target: http://localhost:3002
Endpoint: /formaction
Techniques Tested: Multiple
Successful Techniques: 5 techniques detected vulnerability
Status: ⚠️ VULNERABLE
The target appears to be vulnerable to CVE-2025-55182.
Techniques that detected vulnerability:
-> Gadget: fs#constructor
-> Gadget: vm#runInThisContext
-> Gadget: child_process#execSync
-> Gadget: module#_load
-> Gadget: fs#readFileSync
Recommendation: Apply security patches immediately.
======================================================================
# uv run check http://localhost:8000
======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================
[*] Testing http://localhost:8000/formaction
[*] Testing all detection techniques...
→ Gadget: fs#constructor: ✗ Not vulnerable
→ Gadget: vm#runInThisContext: ✗ Not vulnerable
→ Gadget: child_process#execSync: ✗ Not vulnerable
→ Gadget: module#_load: ✗ Not vulnerable
→ Gadget: fs#readFileSync: ✗ Not vulnerable
→ Gadget: util#promisify: ✗ Not vulnerable
→ Safe Side-Channel Detection: ✗ Not vulnerable
→ RCE PoC (Unix/Linux): ✗ Not vulnerable
→ RCE PoC (Windows): ✗ Not vulnerable
→ RCE with WAF Bypass (Unix/Linux): ✗ Not vulnerable
→ RCE with WAF Bypass (Windows): ✗ Not vulnerable
→ Advanced WAF Bypass (Unix/Linux): ✗ Not vulnerable
======================================================================
DETECTION RESULTS
======================================================================
Target: http://localhost:8000
Endpoint: /formaction
Techniques Tested: Multiple
Status: ✓ NOT VULNERABLE
The target does not appear to be vulnerable to CVE-2025-55182.
All detection techniques failed to confirm vulnerability.
======================================================================
Das Skript ermöglicht es, mehrere Hosts gleichzeitig zu testen.