
CVE-2025-55182 및 CVE-2025-66478을 위한 수동 취약점 스캐너로, 프레임워크 핑거프린팅, 버전 분석, RSC 엔드포인트 프로빙을 통해 React Server Components의 인증되지 않은 RCE를 탐지합니다.
React Server Components Flight 프로토콜 원격 코드 실행 탐지 도구
이 스캐너는 React Server Components(RSC) "Flight" 프로토콜의 심각한 무인증 원격 코드 실행 취약점인 CVE-2025-55182(React) 및 CVE-2025-66478(Next.js)에 잠재적으로 취약한 시스템을 식별합니다.
주요 위험 요소:
React의 Server Components 구현에서 발생하는 심각한 안전하지 않은 역직렬화(insecure deserialization) 취약점입니다. RSC "Flight" 프로토콜이 수신 페이로드의 구조와 유형을 제대로 검증하지 못하여, 공격자가 서버 측 실행에 영향을 미치는 악성 데이터를 주입할 수 있습니다.
| 패키지 | 취약한 버전 | 패치된 버전 |
|---|---|---|
| react-server-dom-webpack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |
| react-server-dom-parcel | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |
| react-server-dom-turbopack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |
| Next.js | 14.3.0-canary.77+, 15.x, 16.0.0-16.0.6 | 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7 |
Attacker → Crafted HTTP POST → RSC Endpoint → Deserialization → RCE
공격에는 임의의 서버 함수(Server Function) 엔드포인트에 대한 특수하게 조작된 HTTP 요청 하나만 필요합니다. 인증이 필요하지 않으며 기본 구성도 취약합니다.
스캐너는 수동적 핑거프린팅(passive fingerprinting) 및 **프로토콜 프로빙(protocol probing)**을 사용하여 잠재적으로 취약한 시스템을 식별합니다. 실제 악용은 시도하지 않습니다.
┌─────────────────────────────────────────────────────────────────┐
│ DETECTION PIPELINE │
├─────────────────────────────────────────────────────────────────┤
│ │
│ 1. Framework Detection │
│ ├── HTTP Headers (X-Powered-By: Next.js) │
│ ├── Page Source (__NEXT_DATA__, react artifacts) │
│ └── Build Manifests │
│ │
│ 2. Version Fingerprinting │
│ ├── Embedded version strings in JS bundles │
│ ├── Package version patterns │
│ └── Build manifest analysis │
│ │
│ 3. RSC Endpoint Discovery │
│ ├── Send RSC headers (RSC: 1, Accept: text/x-component) │
│ ├── Analyze response Content-Type │
│ └── Detect Flight protocol markers in response │
│ │
│ 4. Server Actions Probing │
│ ├── POST request with minimal Flight payload │
│ ├── Check for deserialization processing │
│ └── Identify action endpoints │
│ │
│ 5. Vulnerability Assessment │
│ ├── Correlate version with known vulnerable ranges │
│ ├── Weight RSC endpoint presence │
│ └── Generate confidence-scored verdict │
│ │
└─────────────────────────────────────────────────────────────────┘
| 지표 | 탐지 방법 | 신뢰도 |
|---|---|---|
X-Powered-By: Next.js | HTTP 헤더 검사 | 높음 |
__NEXT_DATA__ 스크립트 태그 | HTML 소스 파싱 | 높음 |
/_next/ 에셋 경로 | HTML 소스 파싱 | 중간 |
| React 하이드레이션 마커 | HTML 소스 파싱 | 중간 |
Flight 프로토콜은 특정한 와이어 포맷을 사용합니다:
0:["$","div",null,{"children":"Hello"}]
1:["$","$L1",null,{}]
2:{"name":"ServerComponent"}
스캐너는 다음을 찾습니다:
text/x-component 콘텐츠 유형{number}:{payload}$, $L, $F, $@, $undefined다음 위치에서 버전 패턴을 검색합니다:
/_next/static/chunks/)[email protected])requests 라이브러리# Clone or download the scanner files
# Install dependencies
pip install -r requirements.txt
# Verify installation
python3 cve-2025-55182-scanner.py --help
# Single target
python3 cve-2025-55182-scanner.py -t https://example.com
# With verbose output
python3 cve-2025-55182-scanner.py -t https://example.com -v
# Create targets file (one URL per line)
echo "https://app1.example.com" > targets.txt
echo "https://app2.example.com" >> targets.txt
# Scan all targets
python3 cve-2025-55182-scanner.py -f targets.txt -o results.json
python3 cve-2025-55182-scanner.py -t https://example.com \
--timeout 15 \
--threads 10 \
--user-agent "SecurityAudit/1.0" \
-v \
-o scan_results.json
| 옵션 | 설명 | 기본값 |
|---|---|---|
-t, --target | 단일 대상 URL | - |
-f, --file | 대상 목록 파일 | - |
-o, --output | JSON 출력 파일 | - |
-v, --verbose | 상세 증거 표시 | False |
--timeout | 요청 시간 제한(초) | 10 |
--threads | 동시 스레드 수 | 5 |
--verify-ssl | SSL 인증서 확인 | False |
--user-agent | 사용자 지정 User-Agent | Mozilla/5.0... |
--no-banner | 배너 숨기기 | False |
더 심층적인 프로토콜 분석을 위해:
python3 rsc_analyzer.py https://example.com 2>/dev/null
이 모듈은 상세한 Flight 프로토콜 분석과 구성 요소 열거를 제공합니다.
| 상태 | 의미 | 필요한 조치 |
|---|---|---|
| 🔴 VULNERABLE | 취약한 버전 감지 확인됨 | 즉시 패치 |
| 🔴 LIKELY_VULNERABLE | RSC가 포함된 React 19.x, 취약 범위 내 버전 | 긴급 패치 |
| 🟡 POTENTIALLY_VULNERABLE | RSC 엔드포인트 발견, 버전 불명 | 조사 및 패치 |
| 🟢 NOT_VULNERABLE | 패치된 버전 확인됨 | 업데이트 모니터링 |
| 🔵 UNKNOWN | 상태 확인 불가 | 수동 검증 필요 |
| ⚪ ERROR | 스캔 실패 | 재시도 또는 수동 확인 |
======================================================================
Target: https://app.example.com
Status: VULNERABLE
Framework: Next.js
Version: 19.1.0
RSC Endpoints: /, /_next/data
Evidence:
- X-Powered-By header: Next.js
- React version detected: 19.1.0
- RSC Flight response at / (Content-Type: text/x-component)
- Flight protocol markers detected at /
Recommendations:
→ CRITICAL: Immediate patching required!
→ Upgrade React to 19.0.1, 19.1.2, or 19.2.1
→ Upgrade Next.js to latest patched version (15.0.5+, 16.0.7)
→ Enable WAF rules to block malicious RSC payloads
→ Monitor for anomalous POST requests to RSC endpoints
======================================================================
{
"target": "https://app.example.com",
"status": "VULNERABLE",
"framework": "Next.js",
"version": "19.1.0",
"rsc_endpoints": ["/", "/_next/data"],
"evidence": [
"X-Powered-By header: Next.js",
"React version detected: 19.1.0",
"RSC Flight response at / (Content-Type: text/x-component)"
],
"recommendations": [
"CRITICAL: Immediate patching required!",
"Upgrade React to 19.0.1, 19.1.2, or 19.2.1"
]
}