由 Rapticore Security Research Team 开发的安全评估工具包,用于检测 React Server Components (RSC) 漏洞,包括 CVE-2025-55182 (React2Shell) - 一个严重的远程代码执行漏洞。
本工具包提供两种专用工具:
| 工具 | 描述 |
|---|---|
ore_rsc.py | 快速 RSC 端点扫描器,用于快速评估 |
ore_react2shell.py | 完整的评估套件,包含子域名枚举和报告生成 |
https://github.com/user-attachments/assets/5be7661b-515c-46b4-ade4-8e88fdff6528
扫描器检测测试 Next.js 应用程序中的 CVE-2025-55182 (React2Shell) 漏洞。
CVE-2025-55182 (React2Shell) 是一个影响 React Server Components 的严重 RCE 漏洞:
| 受影响的包 | 受影响版本 | 修复版本 |
|---|---|---|
| react-server-dom-webpack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1+ |
| react-server-dom-parcel | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1+ |
| react-server-dom-turbopack | 19.0.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1+ |
ore_rsc.py)ore_react2shell.py)# 克隆仓库
git clone https://github.com/rapticore/ore_react2shell_scanner.git
cd ore_react2shell_scanner
# 创建虚拟环境
python3 -m venv env
source env/bin/activate # 在 Windows 上:env\Scripts\activate
# 安装依赖
pip install aiohttp jinja2
# 可选:安装 subfinder 用于子域名枚举
go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
ore_rsc.py 快速扫描# 单域名扫描
python ore_rsc.py example.com
# 多个域名
python ore_rsc.py example.com api.example.com
# 从文件扫描
python ore_rsc.py -f subdomains.txt
# 深度扫描(扩展路径)
python ore_rsc.py example.com --deep
# 主动验证(发送 PoC 载荷)
python ore_rsc.py example.com --verify
# 安全侧信道检查(非利用性)
python ore_rsc.py example.com --safe-check
# JSON 输出
python ore_rsc.py example.com --format json -o results.json
ore_react2shell.py 完整评估# 完整评估,包含子域名枚举
# 结果保存至:results/example_com_{timestamp}/
python ore_react2shell.py --domain example.com
# 使用现有子域名列表
python ore_react2shell.py --domain example.com -f subdomains.txt
# 多个根域名
python ore_react2shell.py --domain example.com --domain example.org
# 带主动验证
python ore_react2shell.py --domain example.com --verify
# 安全侧信道检查
python ore_react2shell.py --domain example.com --safe-check
# 跳过子域名枚举
python ore_react2shell.py --domain example.com --skip-enum
# 自定义输出目录
python ore_react2shell.py --domain example.com -o ./reports
报告按域名和时间戳自动组织:
results/
└── example_com_20250106_143052/
├── rsc_assessment.html # 交互式 HTML 报告
├── rsc_assessment.json # 机器可读的 JSON
├── rsc_assessment.csv # 电子表格格式
└── rsc_assessment_executive_summary.txt # 文本摘要
| 选项 | 描述 |
|---|---|
domains | 要扫描的域名 |
-f, --file | 包含域名的文件(每行一个) |
-c, --concurrency | 并发请求数(默认:20) |
-t, --timeout | 请求超时秒数(默认:25) |
--deep | 深度扫描,使用扩展路径 |
--verify | 主动验证 - 发送 RCE PoC 载荷 |
--safe-check | 安全侧信道验证 |
--waf-bypass | WAF 绕过模式,使用垃圾数据 |
-o, --output | 输出文件路径 |
--format | 输出格式:console、json、csv |
| 选项 | 描述 |
|---|---|
-d, --domain | 要评估的目标域名(必需) |
-f, --file | 包含子域名的文件 |
--skip-enum | 跳过子域名枚举 |
-c, --concurrency | 并发请求数(默认:30) |
--deep | 深度扫描,使用扩展路径 |
--verify | 主动验证模式 |
--safe-check | 安全侧信道验证 |
-o, --output | 输出基目录(默认:results) |
--format | 输出格式:html、json、csv、txt、all |
扫描器实现了健壮的验证逻辑以处理不稳定的服务器:
扫描器通过以下方式检测 RSC 端点:
text/x-component、text/x-rsc、text/x-flightx-nextjs-cache、rsc、next-action 等0:、1:)、React 引用($)$ACTION_ID、formAction 属性| 风险等级 | 标准 |
|---|---|
| 严重 | 通过 --verify 确认可利用 |
| 高 | 通过 --safe-check 可能容易受攻击 |
| 中 | 具有 server actions 的 RSC 端点 |
| 低 | 检测到 RSC 端点 |
| 信息 | 存在 RSC 指示器 |
如果检测到易受攻击的端点:
react-server-dom-* 升级到修复版本(19.0.1、19.1.2、19.2.1+)本工具仅用于已授权的安全评估。仅在你拥有或已获得明确书面授权的域名上使用。
Rapticore Security Research Team 不对滥用行为承担任何责任。
由 Rapticore Security Research Team 开发