Meta React Server Components是美国Meta公司的一系列组件。 Meta React Server Components 19.0.0版本、19.1.0版本、19.1.1版本和19.2.0版本存在安全漏洞,该漏洞源于HTTP请求反序列化不当,可能导致远程代码执行。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| Meta | react-server-dom-parcel | 19.0.0≤ 19.0.0 |
affected |
19.1.0≤ 19.1.1 |
affected | ||
19.2.0≤ 19.2.0 |
affected | ||
| Meta | react-server-dom-turbopack | 19.0.0≤ 19.0.0 |
affected |
19.1.0≤ 19.1.1 |
affected | ||
19.2.0≤ 19.2.0 |
affected | ||
| Meta | react-server-dom-webpack | 19.0.0≤ 19.0.0 |
affected |
19.1.0≤ 19.1.1 |
affected | ||
19.2.0≤ 19.2.0 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Meta | react-server-dom-webpack | 19.0.0 ~ 19.0.0 | - |
|
| Meta | react-server-dom-turbopack | 19.0.0 ~ 19.0.0 | - |
|
| Meta | react-server-dom-parcel | 19.0.0 ~ 19.0.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | React Server Components 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain a remote code execution caused by unsafe deserialization of payloads from HTTP requests to Server Function endpoints, letting unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55182.yaml | POC详情 |
| 2 | Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server Components (RSC) “Flight” protocol. | https://github.com/BankkRoll/Quickcheck-CVE-2025-55182-React-and-CVE-2025-66478-Next.js | POC详情 |
| 3 | CVE-2025-55182 POC | https://github.com/ejpir/CVE-2025-55182-research | POC详情 |
| 4 | CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface | https://github.com/sickwell/CVE-2025-55182 | POC详情 |
| 5 | A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications | https://github.com/fatguru/CVE-2025-55182-scanner | POC详情 |
| 6 | CVE-2025-55182 | https://github.com/Ashwesker/Blackash-CVE-2025-55182 | POC详情 |
| 7 | CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface | https://github.com/atastycookie/CVE-2025-55182 | POC详情 |
| 8 | None | https://github.com/santihabib/CVE-2025-55182-analysis | POC详情 |
| 9 | None | https://github.com/xkillbit/cve-2025-55182-scanner | POC详情 |
| 10 | Testing the React Server Components RCE (CVE-2025-55182) | https://github.com/rpjboyarski/java4script | POC详情 |
| 11 | React2Shell Proof of Concept | https://github.com/whiteov3rflow/CVE-2025-55182-poc | POC详情 |
| 12 | This POC demonstrates CVE-2025-55182 using actual `react-server-dom-webpack@19.0.0` vulnerable code. | https://github.com/Pa2sw0rd/exploit-CVE-2025-55182-poc | POC详情 |
| 13 | CVE-2025-55182 | https://github.com/kk12-30/CVE-2025-55182 | POC详情 |
| 14 | For CVE-2025-55182 and CVE-2025-66478 Security Response | https://github.com/heiheishushu/rsc_detect_CVE-2025-55182 | POC详情 |
| 15 | CVE-2025-55182 漏洞利用GUI,PoC / Exploit for CVE-2025-55182 & CVE-2025-66478 | https://github.com/songsanggggg/CVE-2025-55182 | POC详情 |
| 16 | 检测针对 CVE-2025-55182(React 服务器组件远程代码执行漏洞)的扫描器 | https://github.com/M0onPu15e/next.js-scanner | POC详情 |
| 17 | a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test and understand the vulnerability. | https://github.com/ThemeHackers/CVE-2025-55182 | POC详情 |
| 18 | a realistic POC demonstrating the missing `hasOwnProperty` check in react-server-dom-webpack@19.0.0 | https://github.com/joshterrill/CVE-2025-55182-realistic-poc | POC详情 |
| 19 | A Comprehensive CVE-2025-55182 Detection and Security Assessment Tool | https://github.com/mingyisecurity-lab/CVE-2025-55182-TOOLS | POC详情 |
| 20 | High-performance exploitation engine for CVE-2025-55182 (React Server Components RCE) | https://github.com/joaonevess/rust-flight | POC详情 |
| 21 | Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Auto-fix, SARIF output, GitHub Actions, Vercel integration, and runtime protection middleware. | https://github.com/gensecaihq/react2shell-scanner | POC详情 |
| 22 | None | https://github.com/sudo-Yangziran/CVE-2025-55182POC | POC详情 |
| 23 | 一款针对 CVE-2025-55182 的独立安全评估工具,基于 Go 开发,提供图形化界面(GUI),用于快速完成漏洞检测与验证。 | https://github.com/Rsatan/CVE-2025-55182-Tools | POC详情 |
| 24 | High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) | https://github.com/assetnote/react2shell-scanner | POC详情 |
| 25 | RCE Auto exploit for CVE-2025-55182 | https://github.com/jf0x3a/CVE-2025-55182-exploit | POC详情 |
| 26 | React/Next.js RCE CVE-2025-55182 checker | https://github.com/aspen-labs/CVE-2025-55182-checker | POC详情 |
| 27 | None | https://github.com/dissy123/cve-2025-55182 | POC详情 |
| 28 | Pre-auth RCE in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. | https://github.com/dwisiswant0/CVE-2025-55182 | POC详情 |
| 29 | See if your endpoint could be vulnerable. | https://github.com/Chelsea486MHz/CVE-2025-55182-test | POC详情 |
| 30 | None | https://github.com/oways/React2shell-CVE-2025-55182-checker | POC详情 |
未找到公开 POC。
登录以生成 AI POCZaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.