
CVE-2025-55182とCVE-2025-66478のためのパッシブ脆弱性スキャナー。フレームワークフィンガープリンティング、バージョン分析、RSCエンドポイントプロービングにより、React Server Componentsにおける認証なしRCEを検出します。
React Server Components Flight Protocol リモートコード実行検出ツール
このスキャナーは、React Server Components (RSC) "Flight" プロトコルにおける重大な認証なしリモートコード実行脆弱性である CVE-2025-55182 (React) および CVE-2025-66478 (Next.js) に対して潜在的に脆弱なシステムを特定します。
主なリスク要因:
React の Server Components 実装における重大な安全でないデシリアライゼーションの脆弱性です。RSC "Flight" プロトコルは、受信ペイロードの構造とタイプを適切に検証できず、攻撃者がサーバー側の実行に影響を与える悪意のあるデータを注入することを可能にします。
| パッケージ | 脆弱なバージョン | 修正済みバージョン |
|---|---|---|
| react-server-dom-webpack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |
| react-server-dom-parcel | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |
| react-server-dom-turbopack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |
| Next.js | 14.3.0-canary.77+, 15.x, 16.0.0-16.0.6 | 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7 |
Attacker → Crafted HTTP POST → RSC Endpoint → Deserialization → RCE
攻撃に必要なのは、任意の Server Function エンドポイントへの特別に細工された HTTP リクエストのみです。認証は不要で、デフォルト設定が脆弱です。
スキャナーは パッシブフィンガープリンティング と プロトコルプロービング を使用して、潜在的に脆弱なシステムを特定します。悪用を試みることはありません。
┌─────────────────────────────────────────────────────────────────┐
│ DETECTION PIPELINE │
├─────────────────────────────────────────────────────────────────┤
│ │
│ 1. Framework Detection │
│ ├── HTTP Headers (X-Powered-By: Next.js) │
│ ├── Page Source (__NEXT_DATA__, react artifacts) │
│ └── Build Manifests │
│ │
│ 2. Version Fingerprinting │
│ ├── Embedded version strings in JS bundles │
│ ├── Package version patterns │
│ └── Build manifest analysis │
│ │
│ 3. RSC Endpoint Discovery │
│ ├── Send RSC headers (RSC: 1, Accept: text/x-component) │
│ ├── Analyze response Content-Type │
│ └── Detect Flight protocol markers in response │
│ │
│ 4. Server Actions Probing │
│ ├── POST request with minimal Flight payload │
│ ├── Check for deserialization processing │
│ └── Identify action endpoints │
│ │
│ 5. Vulnerability Assessment │
│ ├── Correlate version with known vulnerable ranges │
│ ├── Weight RSC endpoint presence │
│ └── Generate confidence-scored verdict │
│ │
└─────────────────────────────────────────────────────────────────┘
| インジケーター | 検出方法 | 信頼度 |
|---|---|---|
X-Powered-By: Next.js | HTTP ヘッダー検査 | 高 |
__NEXT_DATA__ script タグ | HTML ソース解析 | 高 |
/_next/ アセットパス | HTML ソース解析 | 中 |
| React ハイドレーションマーカー | HTML ソース解析 | 中 |
Flight プロトコルは特定のワイヤフォーマットを使用します:
0:["$","div",null,{"children":"Hello"}]
1:["$","$L1",null,{}]
2:{"name":"ServerComponent"}
スキャナーは以下を探します:
text/x-component Content-Type{number}:{payload}$, $L, $F, $@, $undefined次の場所でバージョンパターンを検索します:
/_next/static/chunks/)[email protected])requests ライブラリ# Clone or download the scanner files
# Install dependencies
pip install -r requirements.txt
# Verify installation
python3 cve-2025-55182-scanner.py --help
# Single target
python3 cve-2025-55182-scanner.py -t https://example.com
# With verbose output
python3 cve-2025-55182-scanner.py -t https://example.com -v
# Create targets file (one URL per line)
echo "https://app1.example.com" > targets.txt
echo "https://app2.example.com" >> targets.txt
# Scan all targets
python3 cve-2025-55182-scanner.py -f targets.txt -o results.json
python3 cve-2025-55182-scanner.py -t https://example.com \
--timeout 15 \
--threads 10 \
--user-agent "SecurityAudit/1.0" \
-v \
-o scan_results.json
| オプション | 説明 | デフォルト |
|---|---|---|
-t, --target | 単一ターゲットURL | - |
-f, --file | ターゲットリストのファイル | - |
-o, --output | JSON出力ファイル | - |
-v, --verbose | 詳細な証拠を表示 | False |
--timeout | リクエストタイムアウト(秒) | 10 |
--threads | 同時スレッド数 | 5 |
--verify-ssl | SSL証明書を検証 | False |
--user-agent | カスタムUser-Agent | Mozilla/5.0... |
--no-banner | バナーを抑制 | False |
より深いプロトコル分析のために:
python3 rsc_analyzer.py https://example.com 2>/dev/null
これにより、詳細な Flight プロトコル分析とコンポーネントの列挙が提供されます。
| ステータス | 意味 | 必要なアクション |
|---|---|---|
| 🔴 VULNERABLE | 脆弱なバージョンが確認されました | 即時パッチ適用 |
| 🔴 LIKELY_VULNERABLE | React 19.x で RSC が有効、脆弱性範囲内のバージョン | 緊急パッチ適用 |
| 🟡 POTENTIALLY_VULNERABLE | RSC エンドポイントが見つかりましたが、バージョン不明 | 調査とパッチ適用 |
| 🟢 NOT_VULNERABLE | 修正済みバージョンを確認 | アップデートを監視 |
| 🔵 UNKNOWN | ステータスを判定できませんでした | 手動確認が必要 |
| ⚪ ERROR | スキャン失敗 | 再試行または手動確認 |
======================================================================
Target: https://app.example.com
Status: VULNERABLE
Framework: Next.js
Version: 19.1.0
RSC Endpoints: /, /_next/data
Evidence:
- X-Powered-By header: Next.js
- React version detected: 19.1.0
- RSC Flight response at / (Content-Type: text/x-component)
- Flight protocol markers detected at /
Recommendations:
→ 重大: 即時パッチ適用が必要!
→ React を 19.0.1, 19.1.2, または 19.2.1 にアップグレード
→ Next.js を最新の修正版 (15.0.5+, 16.0.7) にアップグレード
→ WAF ルールを有効にして悪意のある RSC ペイロードをブロック
→ RSC エンドポイントへの異常な POST リクエストを監視
======================================================================
{
"target": "https://app.example.com",
"status": "VULNERABLE",
"framework": "Next.js",
"version": "19.1.0",
"rsc_endpoints": ["/", "/_next/data"],
"evidence": [
"X-Powered-By header: Next.js",
"React version detected: 19.1.0",
"RSC Flight response at / (Content-Type: text/x-component)"
],
"recommendations": [
"CRITICAL: Immediate patching required!",
"Upgrade React to 19.0.1, 19.1.2, or 19.2.1"
]
}