Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
react2shell-scanner — 检测 React Server Components 中的 CVE-2025-55182 (React2Shell) RCE 漏洞。快速、准确的扫描器,零误报。 | Kitploit
工具/GitHubGitHub/nxgn-kd01/react2shell-scanner
漏洞扫描器代码分析漏洞利用Web应用程序漏洞利用DevSecOps供应链安全
GitHubnxgn-kd01/react2shell-scanner

react2shell-scanner

检测 React Server Components 中的 CVE-2025-55182 (React2Shell) RCE 漏洞。快速、准确的扫描器,零误报。

查看仓库
37个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

🚨 React2Shell 扫描器

React 服务端组件中的 CVSS 10.0 RCE。你的 React 19 应用存在漏洞吗?

用于检测 CVE-2025-55182(React2Shell)的快速、精准扫描器——这是一个已被在野利用的严重远程代码执行漏洞。凭借智能的服务端组件检测实现零误报。

CVSS Score License: MIT GitHub Issues GitHub Stars PRs Welcome

🚨 关于 React2Shell(CVE-2025-55182)

React2Shell 是 React 服务端组件中的一个**最高严重级别(CVSS 10.0)**漏洞,允许未经身份验证的远程代码执行。攻击者可通过向服务端函数端点发送特制的 HTTP 请求来利用此漏洞。

关键信息:

  • 受影响: React 19.x、Next.js 14-16.x、react-router、waku、@parcel/rsc、expo
  • 攻击向量: 网络(无需身份验证)
  • 影响: 服务器完全失陷(RCE)
  • 披露时间: 2025 年 12 月 3 日
  • 可利用性: 默认配置下成功率接近 100%
  • 相关 CVE: CVE-2025-55184(DoS)、CVE-2025-55183(源码泄露)、CVE-2025-67779

⚠️ 重要说明: 只有 React 19.x 易受攻击。React 18.x 及更早版本不受影响。

⚡ 快速开始(30 秒)

root@kitploit:~
# Option A: Node.js scanner (recommended - cross-platform, no dependencies)
npx react2shell-scanner /path/to/your/project

# Option B: Direct download and run
curl -sSL https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js > scan.js
node scan.js /path/to/your/project

# Option C: Clone and run
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner
node scan.js /path/to/your/project

数秒内出结果: 🚨 存在漏洞 | ⚠️ 存在警告 | ✅ 安全

📋 该扫描器检查什么

该工具执行智能漏洞检测:

1. React 版本分析 🔴 严重

  • 检测易受攻击的 React 19.0.0、19.1.0、19.1.1、19.2.0
  • 确认 React 18.x 应用是安全的(防止误报)
  • 识别 react-server-dom-* 包

2. 框架配置检查 🟡 警告

  • 扫描 Next.js 14.x-canary 至 16.x 版本
  • 检测 react-router、waku、@parcel/rsc、@vitejs/plugin-rsc、rwsdk、expo
  • 在需要时验证 React 19 依赖
  • 检测静态导出模式(服务端组件已禁用 = 安全)

3. 服务端函数检测 🔍 深度分析

  • 扫描源文件中的 'use server' 指令
  • 识别包含服务端函数的文件
  • 仅标记实际使用服务端组件的项目
  • 注意: 动态导入的服务端函数需要人工审查

4. 智能防误报 ✅ 精准

  • 仅标记同时具备 React 19 + 服务端组件 + 'use server' 指令的应用
  • 为边缘情况提供上下文说明
  • 解释项目为何存在/不存在漏洞

5. 多项目扫描 📁 规模化

  • 递归目录扫描
  • 检测 npm、yarn 和 pnpm 项目
  • 生成针对具体项目的修复命令

🎯 扫描器特性

受影响版本

React:

  • 19.0.0、19.1.0、19.1.1、19.2.0

React Server DOM 包:

  • react-server-dom-webpack 19.0.0 - 19.2.0
  • react-server-dom-parcel 19.0.0 - 19.2.0
  • react-server-dom-turbopack 19.0.0 - 19.2.0

Next.js:

  • 14.0.0 至 14.2.34
  • 14.3.0-canary.0 至 14.3.0-canary.87
  • 15.0.0 至 15.0.6
  • 15.1.0 至 15.1.8
  • 15.2.0 至 15.2.5
  • 15.3.0 至 15.3.5
  • 15.4.0 至 15.4.7
  • 15.5.0 至

其他受影响框架(根据 React 官方公告):

  • react-router 7.0.0 - 7.1.3
  • waku 0.21.0 - 0.21.5
  • @parcel/rsc 2.12.0 - 2.13.2
  • @vitejs/plugin-rsc 0.1.0 - 0.2.0
  • rwsdk(Redwood SDK)0.1.0 - 0.4.0
  • expo 52.0.0 - 52.0.9

已修补版本

React: 19.2.1 或更高版本

Next.js:

  • 14.2.35+、14.3.0-canary.88+
  • 15.0.7+、15.1.9+、15.2.6+、15.3.6+、15.4.8+、15.5.7+
  • 16.0.10+

其他框架:

  • react-router:7.1.4+
  • waku:0.21.6+
  • @parcel/rsc:2.13.3+
  • @vitejs/plugin-rsc:0.2.1+
  • rwsdk:0.4.1+
  • expo:52.0.10+

🚀 开始使用

前置要求

Node.js 扫描器(推荐):

  • Node.js 12+(跨平台,无依赖)

Bash 扫描器:

  • Bash 3.2+(macOS/Linux)
  • jq(JSON 处理器)
root@kitploit:~
# Install jq (if using Bash scanner)
# macOS
brew install jq

# Ubuntu/Debian
sudo apt-get install jq

# RHEL/CentOS
sudo yum install jq

第 1 步:获取扫描器

选项 A:克隆(推荐普通用户)

root@kitploit:~
# Clone the repository
git clone https://github.com/nxgn-kd01/react2shell-scanner.git
cd react2shell-scanner

# Make scripts executable
chmod +x scan.sh scan.js

选项 B:Fork(推荐贡献者)

root@kitploit:~
# Fork on GitHub (click "Fork" button on repository page)
# Then clone your fork
git clone https://github.com/YOUR_USERNAME/react2shell-scanner.git
cd react2shell-scanner

# Make scripts executable
chmod +x scan.sh scan.js

# Add upstream remote to stay updated
git remote add upstream https://github.com/nxgn-kd01/react2shell-scanner.git

选项 C:直接下载

root@kitploit:~
# Node.js version (recommended - cross-platform)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.js
chmod +x scan.js

# Bash version (Unix/Linux/macOS only)
curl -O https://raw.githubusercontent.com/nxgn-kd01/react2shell-scanner/main/scan.sh
chmod +x scan.sh

💻 使用方法

第 2 步:运行扫描器

🔍 扫描当前目录:

root@kitploit:~
# Using Node.js (recommended)
node scan.js

# Using Bash
./scan.sh

📁 扫描指定项目:

root@kitploit:~
node scan.js /path/to/project
./scan.sh /path/to/project

🗂️ 递归扫描(所有子目录):

root@kitploit:~
node scan.js -r
./scan.sh -r

高级选项

JSON 输出(用于自动化):

root@kitploit:~
node scan.js --json
./scan.sh --json

CI/CD 模式(存在漏洞时以退出码 1 退出):

root@kitploit:~
node scan.js --ci
./scan.sh --ci

详细输出:

root@kitploit:~
node scan.js -v
./scan.sh -v

组合选项:

root@kitploit:~
node scan.js /path/to/projects -r --json --ci
./scan.sh /path/to/projects -r --json --ci

命令行选项

退出码

代码含义
0未发现漏洞
1发现漏洞(使用 --ci 标志时)
2发生扫描错误

示例

示例 1:扫描单个项目

root@kitploit:~
$ node scan.js ~/my-react-app

╔════════════════════════════════════════════════════════════╗
║  CVE-2025-55182 Scanner (React2Shell)                      ║
╚════════════════════════════════════════════════════════════╝

Severity: CRITICAL (CVSS 10.0)
Description: Unauthenticated RCE in React Server Components

Scan Summary:
  Total projects: 1
  Vulnerable: 1
  Safe: 0

⚠ VULNERABLE PROJECTS FOUND:

1. /Users/user/my-react-app
   └─ react 19.0.0 → 19.2.1
   └─ next 15.0.3 → 15.0.5

   Fix command:
   $ cd /Users/user/my-react-app
   $ npm install [email protected] [email protected]

示例 2:使用 JSON 输出进行递归扫描

root@kitploit:~
$ node scan.js ~/projects -r --json > results.json
root@kitploit:~
{
  "vulnerability": "CVE-2025-55182",
  "severity": "CRITICAL",
  "cvss": 10.0,
  "scanned": 5,
  "vulnerable": 2,
  "results": [
    {
      "path": "/Users/user/projects/app1",
      "vulnerable": true,
      "packages": [
        {
          "name": "react",
          "version": "19.0.0",
          "fixVersion": "19.2.1"
        }
      ],
      "packageManager": "npm",
      "fixCommands": [
        "cd /Users/user/projects/app1",
        "npm install [email protected]"
      ]
    }
  ]
}

示例 3:CI/CD 集成

.github/workflows/security-scan.yml

root@kitploit:~
name: CVE-2025-55182 Security Scan

on: [push, pull_request]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3

      - name: Set up Node.js
        uses: actions/setup-node@v3
        with:
          node-version: '18'

      - name: Download CVE-2025-55182 Scanner
        run: |
          curl -O https://raw.githubusercontent.com/nxgn-kd01/cve-2025-55182-scanner/main/scan.js
          chmod +x scan.js

      - name: Scan for vulnerabilities
        run: node scan.js --ci

GitLab CI(.gitlab-ci.yml)

root@kitploit:~
security-scan:
  stage: test
  image: node:18
  script:
    - curl -O https://raw.githubusercontent.com/nxgn-kd01/cve-2025-55182-scanner/main/scan.js
    - chmod +x scan.js
    - node scan.js --ci
  allow_failure: false

工作原理

该扫描器执行以下检查:

  1. 定位 Node.js 项目:查找 package.json 文件
  2. 解析依赖:同时解析 dependencies 和 devDependencies
  3. 检查版本:对照已知易受攻击的版本:
    • React 19.0.0、19.1.0、19.1.1、19.2.0
    • React Server DOM 包(相同版本)
    • Next.js 版本范围(14.3.x、15.x、16.x)
  4. 扫描服务端函数:在源文件中查找 'use server' 指令
  5. 验证实际漏洞:检查以下条件:
    • React 版本(仅 React 19 受影响 - React 18 是安全的)
    • 配置(静态导出不使用服务端组件)
    • 是否存在 'use server' 指令(表明正在使用服务端函数)
  6. 检测包管理器(npm、yarn 或 pnpm)
  7. 生成修复命令:附带相应的升级语法
  8. 报告结果:以人类可读或 JSON 格式输出

准确性特性

该扫描器包含智能检测以防止误报:

  • React 版本检查:仅当存在 React 19 时才标记 Next.js 应用(React 18 是安全的)
  • 静态导出检测:使用 output: 'export' 的项目会被标记为可能安全
  • 服务端函数检测:扫描源文件中的 'use server' 指令以确认实际使用了服务端组件
  • 上下文警告:解释项目存在或不存在漏洞的原因
  • 保守策略:对可能需要人工审查的边缘情况发出警告(例如动态导入的服务端函数)

示例输出:

root@kitploit:~
✓ No vulnerable projects found

ℹ Projects with analysis notes:

1. /path/to/project
   ℹ Next.js ^15.1.3 is in vulnerable range, but using React 18 (safe - only React 19 affected)

2. /path/to/another-project
   ℹ Next.js 16.0.5 with React 19 detected, but no 'use server' directives found (likely safe).
     Note: dynamically imported Server Functions require manual review.

修复方法

第 1 步:运行扫描器

root@kitploit:~
node scan.js -r

第 2 步:应用修复命令

对于每个易受攻击的项目,运行建议的修复命令:

root@kitploit:~
cd /path/to/project
npm install [email protected] [email protected]  # Example

或使用 yarn:

root@kitploit:~
yarn upgrade [email protected] [email protected]

或使用 pnpm:

root@kitploit:~
pnpm update [email protected] [email protected]

第 3 步:测试你的应用

root@kitploit:~
npm test
npm run build

第 4 步:验证修复

root@kitploit:~
node scan.js --ci

❓ 常见问题解答

问:这会扫描传递依赖吗?

答:目前,扫描器检查的是 package.json 中的直接依赖。如需深入的依赖扫描,请将此工具与 npm audit 或 yarn audit 结合使用。

问:我在用 React 18,会受影响吗?

答:不会,React 18 不受影响 ✅

CVE-2025-55182 仅影响 React 19.x 的服务端组件。即使使用了处于易受攻击版本范围内的 Next.js 15.x 或 16.x 版本,扫描器也会正确地将 React 18 应用识别为安全。

问:我可以在自动化构建管道中使用它吗?

答:可以! 使用 --ci 标志,扫描器在发现漏洞时会以退出码 1 退出,从而使管道构建失败。请参阅上面的 CI/CD 集成示例。

问:如果无法立即升级怎么办?

答:临时缓解措施(升级是唯一彻底的修复方法):

  1. ⛔ 在应用中禁用服务端组件
  2. 🛡️ 添加 WAF 规则以阻止可疑的 RSC 载荷
  3. 📊 监控日志中的利用尝试
  4. ⏰ 规划紧急升级窗口

⚠️ 重要提示: 这些只是临时措施。请尽快升级到已修补的版本。

问:这个扫描器的准确度如何?

答:非常准确,具备智能防误报能力:

  • ✅ 对照官方 CVE 公告检查精确的版本匹配
  • ✅ 验证 React 19 依赖(防止 React 18 误报)
  • ✅ 检测静态导出配置
  • ✅ 扫描 'use server' 指令以确认实际漏洞
  • ✅ 为边缘情况提供上下文警告

问:动态导入的服务端函数呢?

答:扫描器会检测源文件中的 'use server' 指令。但是,动态导入的服务端函数(通过 import() 在运行时加载)可能无法被静态检测到。如果扫描器报告"未找到 'use server' 指令",但你对服务端函数使用了动态导入,则应手动审查这些文件。扫描器会附带一条备注提醒你这一点。

贡献

欢迎贡献!请随时提交 issue 或拉取请求(pull request)。

运行测试

root@kitploit:~
# Test on sample projects
./test-scanner.sh

支持的框架

该扫描器现可根据 React 官方公告检测所有支持 RSC 的主要框架:

  • ✅ React / react-server-dom-*
  • ✅ Next.js
  • ✅ react-router(支持 RSC API)
  • ✅ waku
  • ✅ @parcel/rsc
  • ✅ @vitejs/plugin-rsc
  • ✅ rwsdk(Redwood SDK)
  • ✅ expo

如需支持其他框架,请提交 issue 或提交 PR。

参考资料

  • React 官方博客:严重安全漏洞
  • NVD CVE-2025-55182
  • Wiz 研究:React2Shell 分析
  • Microsoft:防御 CVE-2025-55182
  • AWS:中国关联组织利用 React2Shell
  • Datadog 安全实验室:CVE-2025-55182 RCE 分析
  • Tenable:CVE-2025-55182 常见问题解答

许可证

MIT 许可证 - 详情请参阅 LICENSE 文件

免责声明

本工具按"原样"提供给社区,用于帮助识别易受攻击的项目。在部署到生产环境之前,请始终验证扫描结果,并在安全环境中测试更新。

支持

如果你觉得此工具有用,请:

  • ⭐ 为这个仓库加星标
  • 🐛 报告问题
  • 🔄 与你的团队分享
  • 🤝 贡献改进

保持安全,并及时更新你的依赖!

下载工具
属性值
CVE IDCVE-2025-55182
名称React2Shell
CVSS 评分10.0(严重)
CVSS 向量AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
攻击向量网络
身份验证无需
影响系统完全失陷
15.5.6
  • 16.0.0 至 16.0.9
  • 选项描述
    -r, --recursive扫描所有子目录中的 Node.js 项目
    -v, --verbose显示详细输出
    --json以 JSON 格式输出结果
    --ci若发现漏洞则以退出码 1 退出(用于 CI/CD)
    -h, --help显示帮助信息