用于检测 React Server Components 和 Next.js Server Actions 中两个严重 RCE 漏洞的 CLI 工具 + Nuclei 模板。
该扫描器基于已公开的 react2shell 漏洞进行了重写。
CVE-2025-55182 – React Server Components 反序列化 RCE
React Flight 反序列化过程中的一个缺陷允许用户控制的引用解析为服务器函数,从而导致远程代码执行。
影响 React 19.0.0–19.2.0。
CVE-2025-66478 – Next.js Server Actions RCE
Next.js 在处理 Server Actions 时继承了相同的不安全反序列化行为,导致相同的 RCE 路径。
影响 Next.js 14.3.0-canary.77 到 16.0.6。
由于易于利用且具有完全的 RCE 影响,两者均被评为 CVSS 10.0。
React 和 Next.js 的更新版本提供了补丁。
仅指纹识别:
python3 scanner.py -u https://example.com --fingerprint-only
回调检测
(使用任何 DNS/HTTP 监听器,包括 Burp Collaborator):
python3 scanner.py -u https://example.com --callback-url https://your-id.oast.pro/r2s
Nuclei 工作流:
nuclei -u https://example.com -w nuclei/react2shell-workflow.yaml
漏洞发现和 PoC 研究由: