目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-55182— Meta React Server Components 安全漏洞

一分钟漏洞结论

影响对象
Meta react-server-dom-webpack
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Meta React Server Components是美国Meta公司的一系列组件。 Meta React Server Components 19.0.0版本、19.1.0版本、19.1.1版本和19.2.0版本存在安全漏洞,该漏洞源于HTTP请求反序列化不当,可能导致远程代码执行。

CVSS 10.0 · Critical KEV · 勒索软件 EPSS 99.80% · P100

影响版本矩阵 9

厂商产品 版本范围状态
Meta react-server-dom-parcel 19.0.0≤ 19.0.0 affected
19.1.0≤ 19.1.1 affected
19.2.0≤ 19.2.0 affected
Meta react-server-dom-turbopack 19.0.0≤ 19.0.0 affected
19.1.0≤ 19.1.1 affected
19.2.0≤ 19.2.0 affected
Meta react-server-dom-webpack 19.0.0≤ 19.0.0 affected
19.1.0≤ 19.1.1 affected
19.2.0≤ 19.2.0 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-55182 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Meta React Server Components 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Meta React Server Components是美国Meta公司的一系列组件。 Meta React Server Components 19.0.0版本、19.1.0版本、19.1.1版本和19.2.0版本存在安全漏洞,该漏洞源于HTTP请求反序列化不当,可能导致远程代码执行。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
Meta react-server-dom-webpack 19.0.0 ~ 19.0.0 -
Meta react-server-dom-turbopack 19.0.0 ~ 19.0.0 -
Meta react-server-dom-parcel 19.0.0 ~ 19.0.0 -

二、漏洞 CVE-2025-55182 的公开POC

# POC 描述 源链接 神龙链接
1 React Server Components 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain a remote code execution caused by unsafe deserialization of payloads from HTTP requests to Server Function endpoints, letting unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55182.yaml POC详情
2 Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server Components (RSC) “Flight” protocol. https://github.com/BankkRoll/Quickcheck-CVE-2025-55182-React-and-CVE-2025-66478-Next.js POC详情
3 CVE-2025-55182 POC https://github.com/ejpir/CVE-2025-55182-research POC详情
4 CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface https://github.com/sickwell/CVE-2025-55182 POC详情
5 A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications https://github.com/fatguru/CVE-2025-55182-scanner POC详情
6 CVE-2025-55182 https://github.com/Ashwesker/Blackash-CVE-2025-55182 POC详情
7 CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface https://github.com/atastycookie/CVE-2025-55182 POC详情
8 None https://github.com/santihabib/CVE-2025-55182-analysis POC详情
9 None https://github.com/xkillbit/cve-2025-55182-scanner POC详情
10 Testing the React Server Components RCE (CVE-2025-55182) https://github.com/rpjboyarski/java4script POC详情
11 React2Shell Proof of Concept https://github.com/whiteov3rflow/CVE-2025-55182-poc POC详情
12 This POC demonstrates CVE-2025-55182 using actual `react-server-dom-webpack@19.0.0` vulnerable code. https://github.com/Pa2sw0rd/exploit-CVE-2025-55182-poc POC详情
13 CVE-2025-55182 https://github.com/kk12-30/CVE-2025-55182 POC详情
14 For CVE-2025-55182 and CVE-2025-66478 Security Response https://github.com/heiheishushu/rsc_detect_CVE-2025-55182 POC详情
15 CVE-2025-55182 漏洞利用GUI,PoC / Exploit for CVE-2025-55182 & CVE-2025-66478 https://github.com/songsanggggg/CVE-2025-55182 POC详情
16 检测针对 CVE-2025-55182(React 服务器组件远程代码执行漏洞)的扫描器 https://github.com/M0onPu15e/next.js-scanner POC详情
17 a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test and understand the vulnerability. https://github.com/ThemeHackers/CVE-2025-55182 POC详情
18 a realistic POC demonstrating the missing `hasOwnProperty` check in react-server-dom-webpack@19.0.0 https://github.com/joshterrill/CVE-2025-55182-realistic-poc POC详情
19 A Comprehensive CVE-2025-55182 Detection and Security Assessment Tool https://github.com/mingyisecurity-lab/CVE-2025-55182-TOOLS POC详情
20 High-performance exploitation engine for CVE-2025-55182 (React Server Components RCE) https://github.com/joaonevess/rust-flight POC详情
21 Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Auto-fix, SARIF output, GitHub Actions, Vercel integration, and runtime protection middleware. https://github.com/gensecaihq/react2shell-scanner POC详情
22 None https://github.com/sudo-Yangziran/CVE-2025-55182POC POC详情
23 一款针对 CVE-2025-55182 的独立安全评估工具,基于 Go 开发,提供图形化界面(GUI),用于快速完成漏洞检测与验证。 https://github.com/Rsatan/CVE-2025-55182-Tools POC详情
24 High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) https://github.com/assetnote/react2shell-scanner POC详情
25 RCE Auto exploit for CVE-2025-55182 https://github.com/jf0x3a/CVE-2025-55182-exploit POC详情
26 React/Next.js RCE CVE-2025-55182 checker https://github.com/aspen-labs/CVE-2025-55182-checker POC详情
27 None https://github.com/dissy123/cve-2025-55182 POC详情
28 Pre-auth RCE in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. https://github.com/dwisiswant0/CVE-2025-55182 POC详情
29 See if your endpoint could be vulnerable. https://github.com/Chelsea486MHz/CVE-2025-55182-test POC详情
30 None https://github.com/oways/React2shell-CVE-2025-55182-checker POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-55182 的情报信息

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-55182

匿名用户
2026-01-15 06:09:46

Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.


发表评论