
CVE‑2025‑55182 Detection
Next.js Action Poisoning → Node.js execSync RCE
This document explains how Suricata rule SID 900304 detects exploitation attempts of CVE‑2025‑55182, a critical vulnerability in Next.js that enables Action Poisoning leading to arbitrary Node.js RCE, specifically through:
_prefix serializerchild_process.execSync()