目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-54782— nest 命令注入漏洞

AI Predicted 5.3 Difficulty: Easy EPSS 48.34% · P99

Public Exploits 1

新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-54782の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
ソース: CVE Program / CVE List V5
脆弱性説明
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP server with an API endpoint that uses an unsafe JavaScript sandbox (safe-eval-like implementation). Due to improper sandboxing and missing cross-origin protections, any malicious website visited by a developer can execute arbitrary code on their local machine. The package adds HTTP endpoints to a locally running NestJS development server. One of these endpoints, /inspector/graph/interact, accepts JSON input containing a code field and executes the provided code in a Node.js vm.runInNewContext sandbox. This is fixed in version 0.2.1.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
在命令中使用的特殊元素转义处理不恰当(命令注入)
ソース: CVE Program / CVE List V5
脆弱性タイトル
nest 命令注入漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
nest是nestjs开源的一个 Node.js 框架,用于使用 TypeScript/JavaScript 构建高效、可扩展和企业级的服务器端应用程序。 nest 0.2.0及之前版本存在命令注入漏洞,该漏洞源于@nestjs/devtools-integration包存在不安全JavaScript沙箱,可能导致远程代码执行。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
nestjsnest < 0.2.1 -

II. CVE-2025-54782の公開POC

#POC説明ソースリンクShenlongリンク
1Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP server with an API endpoint that uses an unsafe JavaScript sandbox (safe-eval-like implementation). Due to improper sandboxing and missing cross-origin protections, any malicious website visited by a developer can execute arbitrary code on their local machine. The package adds HTTP endpoints to a locally running NestJS development server. One of these endpoints, /inspector/graph/interact, accepts JSON input containing a code field and executes the provided code in a Node.js vm.runInNewContext sandbox. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-54782.yamlPOC詳細
2NestJS DevTools Unauthenticated RCEhttps://github.com/nitrixog/CVE-2025-54782POC詳細
3PoC for CVE-2025-54782https://github.com/vxaretra/CVE-2025-54782POC詳細
4CVE-2025-54782https://github.com/DDestinys/CVE-2025-54782POC詳細
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-54782のインテリジェンス情報

登录查看更多情报信息。

CVE-2025-54782 安全博客文章 (1)

IV. 関連脆弱性

V. CVE-2025-54782へのコメント

まだコメントはありません


コメントを残す