
Laboratorio educativo que demuestra CVE-2025-55182: RCE crítico en React Server Components mediante contaminación de prototipos en el protocolo Flight
Laboratorio educativo que demuestra CVE-2025-55182 — una vulnerabilidad crítica (CVSS 10.0) de ejecución remota de código en React Server Components causada por contaminación de prototipos en el deserializador del protocolo Flight.
Aviso legal: Este repositorio es solo para fines educativos y de investigación de seguridad autorizada. El acceso no autorizado a sistemas informáticos es ilegal. El autor no asume ninguna responsabilidad por el mal uso de este material. Úsalo únicamente contra sistemas que poseas o para los que tengas permiso explícito por escrito para probar. Al usar este código, aceptas que eres responsable de tus propias acciones.
# 1. Clone
git clone https://github.com/Jeanback1/react-rsc-cve-2025-55182-lab.git
cd react-rsc-cve-2025-55182-lab
# 2. Start the lab (vulnerable + patched instances)
docker compose up -d
# Wait ~2 minutes for both containers to build and start.
# 3. Exploit the vulnerable instance
python exploit/exploit.py http://localhost:3011 id
# 4. Try the same against the patched instance — it fails
python exploit/exploit.py http://localhost:3012 id
docker compose
┌────────────────────────────────┐
│ │
attacker ────▶│ :3011 → rsc-lab-vulnerable │ React 19.2.0
│ (Server Action) │ ← exploitable
│ │
│ :3012 → rsc-lab-patched │ React 19.2.1
│ (no Server Action) │ ← patched
└────────────────────────────────┘
| Contenedor | Puerto | Versión de React | Server Action | ¿Vulnerable? |
|---|---|---|---|---|
rsc-lab-vulnerable | 3011 | 19.2.0 | Sí | Sí |
rsc-lab-patched | 3012 | 19.2.1 | No | No |
requests (pip install requests)├── docker-compose.yml # Lab orchestration
├── README.md # This file
├── LICENSE
│
├── vulnerable/ # Vulnerable Next.js app
│ ├── Dockerfile
│ ├── package.json # [email protected], [email protected]
│ └── app/
│ ├── layout.tsx
│ ├── page.tsx # Server Component + Server Action
│ └── actions.ts # 'use server' — the attack surface
│
├── patched/ # Patched Next.js app
│ ├── Dockerfile
│ ├── package.json # [email protected], [email protected]
│ └── app/
│ ├── layout.tsx
│ └── page.tsx # Server Component only (no Server Actions)
│
├── exploit/
│ ├── exploit.py # Educational RCE exploit (well-commented)
│ ├── requirements.txt
│ └── pyproject.toml
│
└── docs/
└── CVE-2025-55182.md # Full technical analysis
# Single command execution
python exploit/exploit.py <target> <command>
# Examples
python exploit/exploit.py http://localhost:3011 id
python exploit/exploit.py http://localhost:3011 "cat /etc/passwd"
python exploit/exploit.py http://localhost:3011 "ls -la /app"
El exploit funciona en tres etapas:
__proto__ → contaminar Object.prototype.thenmultipart/form-data a través del endpoint de Server ActionX-Action-Redirect (codificada en base64)| Paquete | Vulnerable | Corregida |
|---|---|---|
react | ≤ 19.2.0 | ≥ 19.2.1 |
react-dom | ≤ 19.2.0 | ≥ 19.2.1 |
react-server-dom-webpack | ≤ 19.2.0 | ≥ 19.2.1 |
Consulta docs/CVE-2025-55182.md para una guía completa:
__proto__ es peligroso