React Server ComponentsÔ¶³Ì´úÂëÖ´Ðзì϶À´Ï® £¬£¬£¬ £¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÌṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2025-12-04

½ñÈÕ £¬£¬£¬ £¬£¬£¬£¬8827Ì«Ñô¼¯Íżà²âµ½Ò»¸ö´æÔÚÓÚReact Server ComponentsÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©,¸Ã·ì϶ÔÚ´¦Öÿͻ§¶Ë·¢Íù·þÎñ¶ËµÄ Flight ºÍ̸ÐòÁл¯¸ºÔØ£¨Payload£©Ê± £¬£¬£¬ £¬£¬£¬£¬²»×ã¶Ô·´ÐòÁл¯¶ÔÏó½á¹¹µÄ°²È«Ð£Ñé»úÔì £¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâPayloadÒªÇó £¬£¬£¬ £¬£¬£¬£¬Å²ÓÃNode.jsÄÚÖÃÄ£¿£¿£¿£¿£¿£¿£¿é £¬£¬£¬ £¬£¬£¬£¬´Ó¶øÔÚ·þÎñÆ÷É϶ñÒâÖ´ÐдúÂëºÍºÅÁî £¬£¬£¬ £¬£¬£¬£¬µ¼Ö·þÎñÆ÷±»ÆëÈ«½ÚÔì¡£¡£¡£¡£¡£¡£¡£¡£


·ìϼûèÊö


CVE-2025-55182 ÊÇÒ»¸ö´æÔÚÓÚ React Server Components£¨RSC£©ÊµÏÖÖеĸßΣԶ³Ì´úÂëÖ´ÐУ¨Remote Code Execution, RCE£©·ì϶ £¬£¬£¬ £¬£¬£¬£¬CVSS v3.1 ÆÀ·ÖΪ 10.0£¨Critical£©¡£¡£¡£¡£¡£¡£¡£¡£

¸Ã·ì϶µÄµ××ÓÔ­ÒòÔÚÓÚReact¹Ù·½ÌṩµÄ·þÎñ¶ËÔËÐÐʱ°ü£¨Èç react-server¡¢react-server-dom-webpack»òreact-server-dom-parsing£©ÔÚ´¦Öÿͻ§¶Ë·¢Íù·þÎñ¶ËµÄFlight ºÍ̸ÐòÁл¯¸ºÔØ£¨Payload£©Ê± £¬£¬£¬ £¬£¬£¬£¬²»×ã¶Ô·´ÐòÁл¯¶ÔÏó½á¹¹µÄ°²È«Ð£Ñé»úÔì¡£¡£¡£¡£¡£¡£¡£¡£

´Ë·ì϶ӵÓÐÒÔϹؼüÌØµã£º

? ÎÞÐèÉí·ÝÈÏÖ¤£º¹¥»÷ÕßÖ»ÐèÄܽӼûRSC½Ó¿Ú£¨Í¨³£Îª¹«¿ªµÄ Web ·ÓÉ£©¼´¿É´¥·¢£»£»£»£»£»£»
ÀûÓÃÃż÷µÍ£º½öÐèÒ»´ÎHTTP POSTÒªÇ󣻣»£»£»£»£»
Ó°ÏìÁìÓò¹ã£ºËùÓÐʹÓùٷ½RSCʵÏֵĿò¼Ü£¨Èç Next.js¡¢Waku µÈ£©¾ùÊÜÓ°Ï죻£»£»£»£»£»
ÈÆ¹ýɳÏ䣺ִÐиߵÍÎÄΪ·þÎñ¶ËNode.js ¹ý³Ì £¬£¬£¬ £¬£¬£¬£¬¿É¶ÁÈ¡»·¾³±äÁ¿¡¢Îļþϵͳ¡¢Êý¾Ý¿âÏνӵÈÃô¸Ð×ÊÔ´¡£¡£¡£¡£¡£¡£¡£¡£


ͼƬ1.png


·ì϶¸´ÏÖ½ØÍ¼


ͼƬ2.png

½â¾ö¹æ»®


Ò»¡¢¹Ù·½½¨¸´¹æ»®


# ËùÓÐЧ»§Ó¦Éý¼¶µ½Æä°ä²¼ÏµÁÐÖÐ×îеIJ¹¶¡°æ±¾£º

npm install next@15.0.5   // for 15.0.x

npm install next@15.1.9   // for 15.1.x

npm install next@15.2.6   // for 15.2.x

npm install next@15.3.6   // for 15.3.x

npm install next@15.4.8   // for 15.4.x

npm install next@15.5.7   // for 15.5.x

npm install next@16.0.7   // for 16.0.x

# ÈôÊÇÄãʹÓõÄÊÇNext.js 14.3.0-canary.77 »ò¸ü¸ß°æ±¾µÄ canary °æ±¾ £¬£¬£¬ £¬£¬£¬£¬Çë½µ¼¶µ½×îеIJ»±ä°æ 14.x£º


npm install next@14

# ¸ü¶àÐÅÏ¢Çë°Ý¼ûNext.js¸üÐÂÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢8827Ì«Ñô¼¯ÍŽâ¾ö¹æ»®


1¡¢8827Ì«Ñô¼¯ÍÅ©ɨ²úÆ·¹æ»®


Ìì¾µ·ì϶ɨÃèϵͳÒÑÓÚ2025-12-04ÉÏÏßCVE-2025-55182רÏî¼ì²âÄ£¿£¿£¿£¿£¿£¿£¿é£º


×Ô¶¯¼ø±ð RSC Í¨Ñ¶Ìصã

»ùÓÚÐÐÎªÖ¸ÎÆÅÐ¶Ï React/Next.js °æ±¾

·Ç·ÛËéÐÔÑéÖ¤ £¬£¬£¬ £¬£¬£¬£¬ÎÞÒµÎñÓ°Ïì

Ö§³Ö API Óë Web ÀûÓÃ×ʲúÅúÁ¿É¨Ãè


ɨÃèÕ½Êõ½¨Ò飺·ì϶¿âÉý¼¶ÖÁ×îа汾wvs_100ºóÏ·¢É¨Ã蹤×÷¡£¡£¡£¡£¡£¡£¡£¡£


ͼƬ3.png


2¡¢8827Ì«Ñô¼¯Íżì²âÀà²úÆ·¹æ»®


¼ì²â²úÆ·ÍŶÓÒѸ´Ïָ÷ì϶ £¬£¬£¬ £¬£¬£¬£¬¸÷¼ì²âϵͳÒÑÓÚ2025-12-04ÉÏÏßCVE-2025-55182רÏî¼ì²âÊÂÎñ¿â£º


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEB°²È«ÀûÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½×îа汾 £¬£¬£¬ £¬£¬£¬£¬¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£


ÊÂÎñ¿âÏÂÔØµØÖ·£º

https://venustech.download.venuscloud.cn/


3¡¢8827Ì«Ñô¼¯ÍÅ×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®


8827Ì«Ñô¼¯ÍÅ×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢ £¬£¬£¬ £¬£¬£¬£¬React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©, Çëʵʱ¶ÔÈë¿â×ʲú½øÐзì϶ÖÎÀí¡£¡£¡£¡£¡£¡£¡£¡£ 


ͼƬ4.png


4¡¢8827Ì«Ñô¼¯ÍŰ²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®


£¨1£©»ùÓÚ¹¥»÷ÐÐΪµÄ¹ØÁª·ÖÎöÕ½Êõ


Óû§Äܹ»Í¨¹ý8827Ì«Ñô¼¯ÍÅÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ £¬£¬£¬ £¬£¬£¬£¬½øÐйØÁª·ÖÎöÕ½ÊõÅäÖà £¬£¬£¬ £¬£¬£¬£¬½áºÏÏÖʵ»·¾³Öвɼ¯µÄϵͳÈÕÖ¾ºÍ°²È«É豸¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø £¬£¬£¬ £¬£¬£¬£¬´Ó¶ø·¢ÏÖ¡°React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£¡£¡£¡£¡£¡£¡£¡£


ÔÚÌ©ºÏµÄƽ̨ÖÐ £¬£¬£¬ £¬£¬£¬£¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡±·ì϶ɨÃ蹤×÷ £¬£¬£¬ £¬£¬£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄ³ÁÒª×ʲú¡£¡£¡£¡£¡£¡£¡£¡£


ͼƬ5.png


ƽ̨¡°¹ØÁª·ÖÎö¡±Ä£¿£¿£¿£¿£¿£¿£¿éÖÐ £¬£¬£¬ £¬£¬£¬£¬Ôö³¤¡°L2_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡± £¬£¬£¬ £¬£¬£¬£¬Í¨¹ý8827Ì«Ñô¼¯Íżì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾ £¬£¬£¬ £¬£¬£¬£¬·¢ÏÖ±í²¿¹¥»÷ÐÐΪ¡£¡£¡£¡£¡£¡£¡£¡£


ͼƬ6.png


ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖÐ £¬£¬£¬ £¬£¬£¬£¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓᣡ£¡£¡£¡£¡£¡£¡£


Ôö³¤¡°L3_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡± £¬£¬£¬ £¬£¬£¬£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÅ×Ú»òÔ̺¬¡°L2_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡± £¬£¬£¬ £¬£¬£¬£¬¹¥»÷Á˾ֵÅ×Ú»òÊôÓÚ¡°¹¥»÷³É¹¦¡± £¬£¬£¬ £¬£¬£¬£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨ £¬£¬£¬ £¬£¬£¬£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶÈ¡£¡£¡£¡£¡£¡£¡£¡£


ͼƬ7.png


£¨2£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé


ƾ¾Ý¶ÔReact Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö £¬£¬£¬ £¬£¬£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î £¬£¬£¬ £¬£¬£¬£¬¸²¸ÇµÄTTPÔ̺¬£º


TA0001-³õʼ½Ó¼û£º T1190ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½

TA0004-ȨÏÞÌáÉý: T1055¹ý³Ì×¢Èë

TA0009-Êý¾ÝÍøÂç: T1005´Ó±¾µØÏµÍ³ÍøÂçÊý¾Ý


ͼƬ8.png


ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦ £¬£¬£¬ £¬£¬£¬£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾 £¬£¬£¬ £¬£¬£¬£¬½øÐÐ×Ô¶¯»¯´ëÖᣡ£¡£¡£¡£¡£¡£¡£


5¡¢8827Ì«Ñô¼¯ÍÅÖն˲úÆ·¹æ»®


8827Ì«Ñô¼¯ÍÅÌì«‘Öն˰²È«Ò»Ì廯£¨EDR£©ÒѸ´Ïָ÷ì϶ £¬£¬£¬ £¬£¬£¬£¬Ìṩ×Ô½ç˵poc £¬£¬£¬ £¬£¬£¬£¬Æ¾¾Ý¹ý³Ì¶¨Î»µ½ÏîÄ¿µØµãÎļþ¼Ð»ñÈ¡node×é¼þ°æ±¾ÐÅÏ¢ £¬£¬£¬ £¬£¬£¬£¬¿É´Ó·þÎñ¶ËÏ·¢poc½øÐÐÈ«ÍøÍ¬²½ÑéÖ¤ £¬£¬£¬ £¬£¬£¬£¬Æ¥Åä·ì϶×ʲú £¬£¬£¬ £¬£¬£¬£¬Ô¤·À·ì϶¹¥»÷·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£



¹Ù·½²¼¸æ£º

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components