React Server ComponentsÔ¶³Ì´úÂëÖ´Ðзì϶À´Ï® £¬GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2025-12-04

½ñÈÕ £¬GA»Æ½ð¼×¼à²âµ½Ò»¸ö´æÔÚÓÚReact Server ComponentsÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©,¸Ã·ì϶ÔÚ´¦Öÿͻ§¶Ë·¢Íù·þÎñ¶ËµÄ Flight ºÍ̸ÐòÁл¯¸ºÔØ£¨Payload£©Ê± £¬²»×ã¶Ô·´ÐòÁл¯¶ÔÏó½á¹¹µÄ°²È«Ð£Ñé»úÔì £¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâPayloadÒªÇó £¬Å²ÓÃNode.jsÄÚÖÃÄ£¿é £¬´Ó¶øÔÚ·þÎñÆ÷É϶ñÒâÖ´ÐдúÂëºÍºÅÁî £¬µ¼Ö·þÎñÆ÷±»ÆëÈ«½ÚÔì¡£


·ìϼûèÊö


CVE-2025-55182 ÊÇÒ»¸ö´æÔÚÓÚ React Server Components£¨RSC£©ÊµÏÖÖеĸßΣԶ³Ì´úÂëÖ´ÐУ¨Remote Code Execution, RCE£©·ì϶ £¬CVSS v3.1 ÆÀ·ÖΪ 10.0£¨Critical£©¡£

¸Ã·ì϶µÄµ××ÓÔ­ÒòÔÚÓÚReact¹Ù·½ÌṩµÄ·þÎñ¶ËÔËÐÐʱ°ü£¨Èç react-server¡¢react-server-dom-webpack»òreact-server-dom-parsing£©ÔÚ´¦Öÿͻ§¶Ë·¢Íù·þÎñ¶ËµÄFlight ºÍ̸ÐòÁл¯¸ºÔØ£¨Payload£©Ê± £¬²»×ã¶Ô·´ÐòÁл¯¶ÔÏó½á¹¹µÄ°²È«Ð£Ñé»úÔì¡£

´Ë·ì϶ӵÓÐÒÔϹؼüÌØµã£º

? ÎÞÐèÉí·ÝÈÏÖ¤£º¹¥»÷ÕßÖ»ÐèÄܽӼûRSC½Ó¿Ú£¨Í¨³£Îª¹«¿ªµÄ Web ·ÓÉ£©¼´¿É´¥·¢£»
ÀûÓÃÃż÷µÍ£º½öÐèÒ»´ÎHTTP POSTÒªÇó£»
Ó°ÏìÁìÓò¹ã£ºËùÓÐʹÓùٷ½RSCʵÏֵĿò¼Ü£¨Èç Next.js¡¢Waku µÈ£©¾ùÊÜÓ°Ï죻
ÈÆ¹ýɳÏ䣺ִÐиߵÍÎÄΪ·þÎñ¶ËNode.js ¹ý³Ì £¬¿É¶ÁÈ¡»·¾³±äÁ¿¡¢Îļþϵͳ¡¢Êý¾Ý¿âÏνӵÈÃô¸Ð×ÊÔ´¡£


ͼƬ1.png


·ì϶¸´ÏÖ½ØÍ¼


ͼƬ2.png

½â¾ö¹æ»®


Ò»¡¢¹Ù·½½¨¸´¹æ»®


# ËùÓÐЧ»§Ó¦Éý¼¶µ½Æä°ä²¼ÏµÁÐÖÐ×îеIJ¹¶¡°æ±¾£º

npm install next@15.0.5   // for 15.0.x

npm install next@15.1.9   // for 15.1.x

npm install next@15.2.6   // for 15.2.x

npm install next@15.3.6   // for 15.3.x

npm install next@15.4.8   // for 15.4.x

npm install next@15.5.7   // for 15.5.x

npm install next@16.0.7   // for 16.0.x

# ÈôÊÇÄãʹÓõÄÊÇNext.js 14.3.0-canary.77 »ò¸ü¸ß°æ±¾µÄ canary °æ±¾ £¬Çë½µ¼¶µ½×îеIJ»±ä°æ 14.x£º


npm install next@14

# ¸ü¶àÐÅÏ¢Çë°Ý¼ûNext.js¸üÐÂÈÕÖ¾¡£


¶þ¡¢GA»Æ½ð¼×½â¾ö¹æ»®


1¡¢GA»Æ½ð¼×©ɨ²úÆ·¹æ»®


Ìì¾µ·ì϶ɨÃèϵͳÒÑÓÚ2025-12-04ÉÏÏßCVE-2025-55182רÏî¼ì²âÄ£¿é£º


×Ô¶¯¼ø±ð RSC Í¨Ñ¶Ìصã

»ùÓÚÐÐÎªÖ¸ÎÆÅÐ¶Ï React/Next.js °æ±¾

·Ç·ÛËéÐÔÑéÖ¤ £¬ÎÞÒµÎñÓ°Ïì

Ö§³Ö API Óë Web ÀûÓÃ×ʲúÅúÁ¿É¨Ãè


ɨÃèÕ½Êõ½¨Ò飺·ì϶¿âÉý¼¶ÖÁ×îа汾wvs_100ºóÏ·¢É¨Ã蹤×÷¡£


ͼƬ3.png


2¡¢GA»Æ½ð¼×¼ì²âÀà²úÆ·¹æ»®


¼ì²â²úÆ·ÍŶÓÒѸ´Ïָ÷ì϶ £¬¸÷¼ì²âϵͳÒÑÓÚ2025-12-04ÉÏÏßCVE-2025-55182רÏî¼ì²âÊÂÎñ¿â£º


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEB°²È«ÀûÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½×îа汾 £¬¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ¡£


ÊÂÎñ¿âÏÂÔØµØÖ·£º

https://venustech.download.venuscloud.cn/


3¡¢GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®


GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢ £¬React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©, Çëʵʱ¶ÔÈë¿â×ʲú½øÐзì϶ÖÎÀí¡£ 


ͼƬ4.png


4¡¢GA»Æ½ð¼×°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®


£¨1£©»ùÓÚ¹¥»÷ÐÐΪµÄ¹ØÁª·ÖÎöÕ½Êõ


Óû§Äܹ»Í¨¹ýGA»Æ½ð¼×Ì©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ £¬½øÐйØÁª·ÖÎöÕ½ÊõÅäÖà £¬½áºÏÏÖʵ»·¾³Öвɼ¯µÄϵͳÈÕÖ¾ºÍ°²È«É豸¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø £¬´Ó¶ø·¢ÏÖ¡°React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£


ÔÚÌ©ºÏµÄƽ̨ÖÐ £¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡±·ì϶ɨÃ蹤×÷ £¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄ³ÁÒª×ʲú¡£


ͼƬ5.png


ƽ̨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖÐ £¬Ôö³¤¡°L2_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡± £¬Í¨¹ýGA»Æ½ð¼×¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾ £¬·¢ÏÖ±í²¿¹¥»÷ÐÐΪ¡£


ͼƬ6.png


ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖÐ £¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓá£


Ôö³¤¡°L3_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡± £¬Ç°ÌáÈÕÖ¾Ãû³ÆµÅ×Ú»òÔ̺¬¡°L2_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡± £¬¹¥»÷Á˾ֵÅ×Ú»òÊôÓÚ¡°¹¥»÷³É¹¦¡± £¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨ £¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶÈ¡£


ͼƬ7.png


£¨2£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé


ƾ¾Ý¶ÔReact Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö £¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î £¬¸²¸ÇµÄTTPÔ̺¬£º


TA0001-³õʼ½Ó¼û£º T1190ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½

TA0004-ȨÏÞÌáÉý: T1055¹ý³Ì×¢Èë

TA0009-Êý¾ÝÍøÂç: T1005´Ó±¾µØÏµÍ³ÍøÂçÊý¾Ý


ͼƬ8.png


ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦ £¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾 £¬½øÐÐ×Ô¶¯»¯´ëÖá£


5¡¢GA»Æ½ð¼×Öն˲úÆ·¹æ»®


GA»Æ½ð¼×Ìì«‘Öն˰²È«Ò»Ì廯£¨EDR£©ÒѸ´Ïָ÷ì϶ £¬Ìṩ×Ô½ç˵poc £¬Æ¾¾Ý¹ý³Ì¶¨Î»µ½ÏîÄ¿µØµãÎļþ¼Ð»ñÈ¡node×é¼þ°æ±¾ÐÅÏ¢ £¬¿É´Ó·þÎñ¶ËÏ·¢poc½øÐÐÈ«ÍøÍ¬²½ÑéÖ¤ £¬Æ¥Åä·ì϶×ʲú £¬Ô¤·À·ì϶¹¥»÷·çÏÕ¡£



¹Ù·½²¼¸æ£º

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components