
Bildungslabor zur Demonstration von CVE-2025-55182: Kritische RCE in React Server Components durch Prototype Pollution im Flight Protocol
Pädagogisches Labor, das CVE-2025-55182 demonstriert – eine kritische (CVSS 10.0) Remote Code Execution-Sicherheitslücke in React Server Components, verursacht durch Prototyp-Verschmutzung im Flight-Protokoll-Deserialisierer.
Haftungsausschluss: Dieses Repository dient ausschließlich zu Bildungs- und autorisierten Sicherheitsforschungszwecken. Unautorisierter Zugriff auf Computersysteme ist illegal. Der Autor übernimmt keine Haftung für Missbrauch dieses Materials. Verwenden Sie es nur gegen Systeme, die Ihnen gehören oder für die Sie eine ausdrückliche schriftliche Erlaubnis zum Testen haben. Durch die Nutzung dieses Codes stimmen Sie zu, dass Sie für Ihre eigenen Handlungen verantwortlich sind.
# 1. Klonen
git clone https://github.com/Jeanback1/react-rsc-cve-2025-55182-lab.git
cd react-rsc-cve-2025-55182-lab
# 2. Labor starten (verwundbare + gepatchte Instanzen)
docker compose up -d
# Warten Sie ~2 Minuten, bis beide Container erstellt und gestartet sind.
# 3. Die verwundbare Instanz ausnutzen
python exploit/exploit.py http://localhost:3011 id
# 4. Versuchen Sie dasselbe gegen die gepatchte Instanz – es schlägt fehl
python exploit/exploit.py http://localhost:3012 id
docker compose
┌────────────────────────────────┐
│ │
attacker ────▶│ :3011 → rsc-lab-vulnerable │ React 19.2.0
│ (Server Action) │ ← exploitable
│ │
│ :3012 → rsc-lab-patched │ React 19.2.1
│ (no Server Action) │ ← patched
└────────────────────────────────┘
| Container | Port | React Version | Server Action | Verwundbar? |
|---|---|---|---|---|
rsc-lab-vulnerable | 3011 | 19.2.0 | Yes | Ja |
rsc-lab-patched | 3012 | 19.2.1 | No | Nein |
requests (pip install requests)├── docker-compose.yml # Labor-Orchestrierung
├── README.md # Diese Datei
├── LICENSE
│
├── vulnerable/ # Verwundbare Next.js-App
│ ├── Dockerfile
│ ├── package.json # [email protected], [email protected]
│ └── app/
│ ├── layout.tsx
│ ├── page.tsx # Server-Komponente + Server Action
│ └── actions.ts # 'use server' – die Angriffsfläche
│
├── patched/ # Gepatchte Next.js-App
│ ├── Dockerfile
│ ├── package.json # [email protected], [email protected]
│ └── app/
│ ├── layout.tsx
│ └── page.tsx # Nur Server-Komponente (keine Server-Aktionen)
│
├── exploit/
│ ├── exploit.py # Pädagogischer RCE-Exploit (gut kommentiert)
│ ├── requirements.txt
│ └── pyproject.toml
│
└── docs/
└── CVE-2025-55182.md # Vollständige technische Analyse
# Einzelne Befehlsausführung
python exploit/exploit.py <target> <command>
# Beispiele
python exploit/exploit.py http://localhost:3011 id
python exploit/exploit.py http://localhost:3011 "cat /etc/passwd"
python exploit/exploit.py http://localhost:3011 "ls -la /app"
Der Exploit funktioniert in drei Schritten:
__proto__-Traversal → Object.prototype.then verschmutzenmultipart/form-data über den Server-Action-EndpunktX-Action-Redirect-Antwortheader (base64-kodiert)| Paket | Verwundbar | Gepatcht |
|---|---|---|
react | ≤ 19.2.0 | ≥ 19.2.1 |
react-dom | ≤ 19.2.0 | ≥ 19.2.1 |
react-server-dom-webpack | ≤ 19.2.0 | ≥ 19.2.1 |
Siehe docs/CVE-2025-55182.md für eine vollständige Anleitung:
__proto__-Traversal gefährlich ist