
React/Next.js 애플리케이션의 CVE-2025-55182용 다중 기술 취약점 탐지기입니다. 가젯 체인, RCE 페이로드 및 WAF 우회 변형을 테스트하여 취약한 Server Actions 엔드포인트를 식별합니다.
React/Next.js 애플리케이션에서 CVE-2025-55182를 위한 포괄적인 취약점 탐지 도구로, 다양한 탐지 기술을 제공합니다.
승인된 보안 테스트 및 연구 목적으로만 사용하세요
이 도구는 다음을 위해 설계되었습니다:
컴퓨터 시스템에 대한 무단 접근은 불법입니다. 테스트 전에 항상 서면 허가를 받으세요.
이 탐지기는 여러 기술을 사용하여 대상 애플리케이션이 CVE-2025-55182에 취약한지 포괄적으로 테스트합니다:
도구는 무해한 작업으로 Node.js 가젯 체인을 테스트합니다:
1+1)echo test)path)/dev/null)테스트 작업:
echo test, 1+1)/dev/null)하지 않는 것:
이 도구는 종속성 관리 및 실행을 위해 uv를 사용합니다.
설치가 필요 없습니다! 복제하고 실행하세요:
git clone <repository-url>
cd CVE-2025-55182/poc
uv run check http://target.com:3000
도구는 첫 실행 시 자동으로 종속성을 설치합니다.
uv run check <target_url>
# Test a target with default settings (tests /formaction endpoint)
uv run check http://localhost:3002
# Specify custom endpoint
uv run check http://localhost:3002 --endpoint /api/formaction
# Test multiple targets from a file
uv run check --file targets.txt
# Save vulnerable hosts to file
uv run check --file targets.txt -o vulnerable.txt
# Increase timeout for slow connections
uv run check http://localhost:3002 --timeout 15
# Disable SSL verification (for self-signed certificates)
uv run check http://localhost:3002 --no-ssl-verify
# Quiet mode (minimal output)
uv run check http://localhost:3002 --quiet
usage: uv run check [-h] [-f FILE] [-e ENDPOINT] [-t TIMEOUT]
[--no-ssl-verify] [-q] [-o OUTPUT] [target]
positional arguments:
target Target URL (e.g., http://target.com:3000)
optional arguments:
-h, --help Show help message and exit
-f, --file FILE File containing target URLs (one per line)
-e, --endpoint API endpoint path (default: /formaction)
-t, --timeout Request timeout in seconds (default: 10)
--no-ssl-verify Disable SSL certificate verification
-q, --quiet Quiet mode (minimal output)
-o, --output OUTPUT Output file to write vulnerable hosts
0 - 대상이 취약하지 않음1 - 대상이 취약함130 - 사용자가 중단 (Ctrl+C)# uv run check http://localhost:3002
======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================
[*] Testing http://localhost:3002/formaction
[*] Testing all detection techniques...
→ Gadget: fs#constructor: ✓ VULNERABLE
→ Gadget: vm#runInThisContext: ✓ VULNERABLE
→ Gadget: child_process#execSync: ✓ VULNERABLE
→ Gadget: module#_load: ✓ VULNERABLE
→ Gadget: fs#readFileSync: ✓ VULNERABLE
→ Gadget: util#promisify: ✗ Not vulnerable
→ Safe Side-Channel Detection: ✗ Not vulnerable
→ RCE PoC (Unix/Linux): ✗ Not vulnerable
→ RCE PoC (Windows): ✗ Not vulnerable
→ RCE with WAF Bypass (Unix/Linux): ✗ Not vulnerable
→ RCE with WAF Bypass (Windows): ✗ Not vulnerable
→ Advanced WAF Bypass (Unix/Linux): ✗ Not vulnerable
======================================================================
DETECTION RESULTS
======================================================================
Target: http://localhost:3002
Endpoint: /formaction
Techniques Tested: Multiple
Successful Techniques: 5 techniques detected vulnerability
Status: ⚠️ VULNERABLE
The target appears to be vulnerable to CVE-2025-55182.
Techniques that detected vulnerability:
-> Gadget: fs#constructor
-> Gadget: vm#runInThisContext
-> Gadget: child_process#execSync
-> Gadget: module#_load
-> Gadget: fs#readFileSync
Recommendation: Apply security patches immediately.
======================================================================
# uv run check http://localhost:8000
======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================
[*] Testing http://localhost:8000/formaction
[*] Testing all detection techniques...
→ Gadget: fs#constructor: ✗ Not vulnerable
→ Gadget: vm#runInThisContext: ✗ Not vulnerable
→ Gadget: child_process#execSync: ✗ Not vulnerable
→ Gadget: module#_load: ✗ Not vulnerable
→ Gadget: fs#readFileSync: ✗ Not vulnerable
→ Gadget: util#promisify: ✗ Not vulnerable
→ Safe Side-Channel Detection: ✗ Not vulnerable
→ RCE PoC (Unix/Linux): ✗ Not vulnerable
→ RCE PoC (Windows): ✗ Not vulnerable
→ RCE with WAF Bypass (Unix/Linux): ✗ Not vulnerable
→ RCE with WAF Bypass (Windows): ✗ Not vulnerable
→ Advanced WAF Bypass (Unix/Linux): ✗ Not vulnerable
======================================================================
DETECTION RESULTS
======================================================================
Target: http://localhost:8000
Endpoint: /formaction
Techniques Tested: Multiple
Status: ✓ NOT VULNERABLE
The target does not appear to be vulnerable to CVE-2025-55182.
All detection techniques failed to confirm vulnerability.
======================================================================
스크립트를 사용하면 여러 호스트를 한 번에 테스트할 수 있습니다.
# Create a file with target URLs (one per line)
echo "http://localhost:3002" > targets.txt
echo "http://localhost:8000" >> targets.txt
# Run batch scan
uv run check --file targets.txt -o vulnerable.txt
출력:
======================================================================
CVE-2025-55182 Vulnerability Detector - Enhanced Edition
Multiple Detection Techniques | Comprehensive Coverage
======================================================================
[*] Loaded 2 target(s) from file
[*] Testing target 1/2
[*] Testing http://localhost:3002/formaction
[*] Testing all detection techniques...
→ Gadget: fs#constructor: ✓ VULNERABLE
→ Gadget: vm#runInThisContext: ✓ VULNERABLE
[... additional techniques ...]
======================================================================
DETECTION RESULTS
======================================================================
Target: http://localhost:3002
Endpoint: /formaction
Techniques Tested: Multiple
Successful Techniques: 5 techniques detected vulnerability
Status: ⚠️ VULNERABLE
[... details ...]
======================================================================
[*] Testing target 2/2
[*] Testing http://localhost:8000/formaction
[*] Testing all detection techniques...
→ Gadget: fs#constructor: ✗ Not vulnerable
[... all techniques fail ...]
----------------------------------------------------------------------
Target: http://localhost:8000
Endpoint: /formaction
Techniques Tested: Multiple