Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2025-55182-checker — Rilevatore di vulnerabilità multi-tecnica per CVE-2025-55182 in applicazioni React/Next.js. Testa catene di gadget, payload RCE e varianti di bypass WAF per identificare endpoint Server Actions vulnerabili. | Kitploit
Strumenti/GitHubGitHub/harness-security-labs/cve-2025-55182-checker
Scanner di VulnerabilitàExploitSfruttamento di Applicazioni WebBypass WAFPenetration TestingSviluppo Payload
GitHubharness-security-labs/cve-2025-55182-checker

CVE-2025-55182-checker

Rilevatore di vulnerabilità multi-tecnica per CVE-2025-55182 in applicazioni React/Next.js. Testa catene di gadget, payload RCE e varianti di bypass WAF per identificare endpoint Server Actions vulnerabili.

Vedi Repository
1159 mesi faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Rilevatore di Vulnerabilità CVE-2025-55182 - Edizione Potenziata

Un tool completo per la rilevazione della vulnerabilità CVE-2025-55182 in applicazioni React/Next.js con molteplici tecniche di rilevamento.

⚠️ Disclaimer Legale

SOLO PER SCOPI AUTORIZZATI DI TEST DI SICUREZZA E RICERCA

Questo tool è progettato per:

  • Impegni di penetration testing autorizzati
  • Ricerca sulla sicurezza in ambienti controllati
  • Scopi educativi
  • Valutazione delle vulnerabilità con la dovuta autorizzazione

L'accesso non autorizzato a sistemi informatici è illegale. Ottenere sempre un'autorizzazione scritta prima di testare.

Caratteristiche

  • Tecniche di Rilevamento Multiple: Test completi con vari approcci
  • Sonde di Gadget Chain: Testa vari percorsi di accesso ai moduli Node.js
  • Operazioni Sicure: Utilizza solo comandi di test innocui e non distruttivi
  • Tecniche di Bypass WAF: Rilevamento avanzato per ambienti protetti
  • Test Batch: Testa più target da un file

Cosa Fa Questo Script

Questo rilevatore testa in modo completo se un'applicazione target è vulnerabile a CVE-2025-55182 utilizzando molteplici tecniche:

✅ Sonde di Gadget Chain (Sicure, Non Distruttive)

Il tool testa le gadget chain di Node.js con operazioni innocue:

  • fs#constructor: Testa l'accesso al costruttore del filesystem (nessun file accesso)
  • vm#runInThisContext: Valuta JavaScript sicuro (1+1)
  • child_process#execSync: Esegue comando innocuo (echo test)
  • module#_load: Carica modulo integrato sicuro (path)
  • fs#readFileSync: Legge file di sistema sicuro (/dev/null)
  • util#promisify: Testa l'accesso alla funzione di utilità

✅ Tecniche di Rilevamento Avanzate

  • Rilevamento Sicuro di Canale Laterale: Rilevamento di pattern di errore non sfruttabili
  • Proof-of-Concept RCE: Test di esecuzione comandi (Unix/Linux e Windows)
  • Varianti di Bypass WAF: Tecniche per eludere i firewall applicativi web
  • Payload Avanzati: Molteplici metodi di costruzione dei payload

⚠️ Cosa Fa il Tool

Operazioni di Test:

  • Esegue comandi sicuri e innocui (echo test, 1+1)
  • Legge file di sistema sicuri (/dev/null)
  • Testa il caricamento dei moduli con moduli integrati
  • Invia molteplici varianti di payload per rilevare la vulnerabilità

NON:

  • Legge file o dati sensibili
  • Scrive o modifica file
  • Esegue comandi distruttivi
  • Lascia tracce o backdoor
  • Sfrutta la vulnerabilità oltre la rilevazione

Installazione

Questo tool utilizza uv per la gestione delle dipendenze e l'esecuzione.

Prerequisiti

  • Python 3.13 o superiore
  • uv (installa da https://github.com/astral-sh/uv)

Avvio Rapido

Nessuna installazione necessaria! Basta clonare ed eseguire:

git clone <repository-url>
cd CVE-2025-55182/poc
uv run check http://target.com:3000

Il tool installerà automaticamente le dipendenze al primo avvio.

Utilizzo

Utilizzo Base

uv run check <target_url>

Esempi

# Test a target with default settings (tests /formaction endpoint)
uv run check http://localhost:3002

# Specify custom endpoint
uv run check http://localhost:3002 --endpoint /api/formaction

# Test multiple targets from a file
uv run check --file targets.txt

# Save vulnerable hosts to file
uv run check --file targets.txt -o vulnerable.txt

# Increase timeout for slow connections
uv run check http://localhost:3002 --timeout 15

# Disable SSL verification (for self-signed certificates)
uv run check http://localhost:3002 --no-ssl-verify

# Quiet mode (minimal output)
uv run check http://localhost:3002 --quiet

Opzioni da Riga di Comando

usage: uv run check [-h] [-f FILE] [-e ENDPOINT] [-t TIMEOUT]
                    [--no-ssl-verify] [-q] [-o OUTPUT] [target]

positional arguments:
  target                Target URL (e.g., http://target.com:3000)

optional arguments:
  -h, --help            Show help message and exit
  -f, --file FILE       File containing target URLs (one per line)
  -e, --endpoint        API endpoint path (default: /formaction)
  -t, --timeout         Request timeout in seconds (default: 10)
  --no-ssl-verify       Disable SSL certificate verification
  -q, --quiet           Quiet mode (minimal output)
  -o, --output OUTPUT   Output file to write vulnerable hosts

Codici di Uscita

  • 0 - Il target NON è vulnerabile
  • 1 - Il target È vulnerabile
  • 130 - Interrotto dall'utente (Ctrl+C)
  • Altro - Errore verificato

Output di Esempio

Target Vulnerabile

# uv run check http://localhost:3002
======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================

[*] Testing http://localhost:3002/formaction
[*] Testing all detection techniques...
  → Gadget: fs#constructor: ✓ VULNERABLE
  → Gadget: vm#runInThisContext: ✓ VULNERABLE
  → Gadget: child_process#execSync: ✓ VULNERABLE
  → Gadget: module#_load: ✓ VULNERABLE
  → Gadget: fs#readFileSync: ✓ VULNERABLE
  → Gadget: util#promisify: ✗ Not vulnerable
  → Safe Side-Channel Detection: ✗ Not vulnerable
  → RCE PoC (Unix/Linux): ✗ Not vulnerable
  → RCE PoC (Windows): ✗ Not vulnerable
  → RCE with WAF Bypass (Unix/Linux): ✗ Not vulnerable
  → RCE with WAF Bypass (Windows): ✗ Not vulnerable
  → Advanced WAF Bypass (Unix/Linux): ✗ Not vulnerable

======================================================================
DETECTION RESULTS
======================================================================
Target:                  http://localhost:3002
Endpoint:                /formaction
Techniques Tested:       Multiple
Successful Techniques:   5 techniques detected vulnerability

Status:                  ⚠️  VULNERABLE

The target appears to be vulnerable to CVE-2025-55182.

Techniques that detected vulnerability:
 -> Gadget: fs#constructor
 -> Gadget: vm#runInThisContext
 -> Gadget: child_process#execSync
 -> Gadget: module#_load
 -> Gadget: fs#readFileSync

Recommendation: Apply security patches immediately.
======================================================================

Target Non Vulnerabile

# uv run check http://localhost:8000
======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================

[*] Testing http://localhost:8000/formaction
[*] Testing all detection techniques...
  → Gadget: fs#constructor: ✗ Not vulnerable
  → Gadget: vm#runInThisContext: ✗ Not vulnerable
  → Gadget: child_process#execSync: ✗ Not vulnerable
  → Gadget: module#_load: ✗ Not vulnerable
  → Gadget: fs#readFileSync: ✗ Not vulnerable
  → Gadget: util#promisify: ✗ Not vulnerable
  → Safe Side-Channel Detection: ✗ Not vulnerable
  → RCE PoC (Unix/Linux): ✗ Not vulnerable
  → RCE PoC (Windows): ✗ Not vulnerable
  → RCE with WAF Bypass (Unix/Linux): ✗ Not vulnerable
  → RCE with WAF Bypass (Windows): ✗ Not vulnerable
  → Advanced WAF Bypass (Unix/Linux): ✗ Not vulnerable

======================================================================
DETECTION RESULTS
======================================================================
Target:                  http://localhost:8000
Endpoint:                /formaction
Techniques Tested:       Multiple

Status:                  ✓ NOT VULNERABLE

The target does not appear to be vulnerable to CVE-2025-55182.
All detection techniques failed to confirm vulnerability.
======================================================================

Test Batch

Lo script consente di testare più host contemporaneamente.

# Create a file with target URLs (one per line)
echo "http://localhost:3002" > targets.txt
echo "http://localhost:8000" >> targets.txt
Scarica lo strumento