React Server ComponentsÔ¶³Ì´úÂëÖ´ÐÐÎó²îÀ´Ï®£¬ £¬£¬£¬ÄϹ¬NGÓéÀÖÌṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2025-12-04

½ñÈÕ£¬ £¬£¬£¬ÄϹ¬NGÓéÀÖ¼à²âµ½Ò»¸ö±£´æÓÚReact Server ComponentsÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-55182£©,¸ÃÎó²îÔÚ´¦Öóͷ£¿Í»§¶Ë·¢ÍùЧÀÍ¶ËµÄ Flight ЭÒéÐòÁл¯¸ºÔØ£¨Payload£©Ê±£¬ £¬£¬£¬È±·¦¶Ô·´ÐòÁл¯¹¤¾ß½á¹¹µÄÇ徲УÑé»úÖÆ£¬ £¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâPayloadÇëÇó£¬ £¬£¬£¬Å²ÓÃNode.jsÄÚÖÃÄ£¿£¿£¿£¿é£¬ £¬£¬£¬´Ó¶øÔÚЧÀÍÆ÷É϶ñÒâÖ´ÐдúÂëºÍÏÂÁ £¬£¬£¬µ¼ÖÂЧÀÍÆ÷±»ÍêÈ«¿ØÖÆ¡£¡£ ¡£¡£¡£¡£


Îó²îÐÎò


CVE-2025-55182 ÊÇÒ»¸ö±£´æÓÚ React Server Components£¨RSC£©ÊµÏÖÖеĸßΣԶ³Ì´úÂëÖ´ÐУ¨Remote Code Execution, RCE£©Îó²î£¬ £¬£¬£¬CVSS v3.1 ÆÀ·ÖΪ 10.0£¨Critical£©¡£¡£ ¡£¡£¡£¡£

¸ÃÎó²îµÄ»ù´¡Ôµ¹ÊÔ­ÓÉÔÚÓÚReact¹Ù·½ÌṩµÄЧÀͶËÔËÐÐʱ°ü£¨Èç react-server¡¢react-server-dom-webpack»òreact-server-dom-parsing£©ÔÚ´¦Öóͷ£¿Í»§¶Ë·¢ÍùЧÀͶ˵ÄFlight Ð­ÒéÐòÁл¯¸ºÔØ£¨Payload£©Ê±£¬ £¬£¬£¬È±·¦¶Ô·´ÐòÁл¯¹¤¾ß½á¹¹µÄÇ徲УÑé»úÖÆ¡£¡£ ¡£¡£¡£¡£

´ËÎó²î¾ßÓÐÒÔÏÂÒªº¦ÌØÕ÷£º

? ÎÞÐèÉí·ÝÈÏÖ¤£º¹¥»÷ÕßÖ»ÐèÄÜ»á¼ûRSC½Ó¿Ú£¨Í¨³£Îª¹ûÕæµÄ Web ·ÓÉ£©¼´¿É´¥·¢£» £»£»£»£»
ʹÓÃÃż÷µÍ£º½öÐèÒ»´ÎHTTP POSTÇëÇó£» £»£»£»£»
Ó°Ïì¹æÄ£¹ã£ºËùÓÐʹÓùٷ½RSCʵÏֵĿò¼Ü£¨Èç Next.js¡¢Waku µÈ£©¾ùÊÜÓ°Ï죻 £»£»£»£»
ÈÆ¹ýɳÏ䣺ִÐÐÉÏÏÂÎÄΪЧÀͶËNode.js Àú³Ì£¬ £¬£¬£¬¿É¶ÁÈ¡ÇéÐαäÁ¿¡¢Îļþϵͳ¡¢Êý¾Ý¿âÅþÁ¬µÈÃô¸Ð×ÊÔ´¡£¡£ ¡£¡£¡£¡£


ͼƬ1.png


Îó²î¸´ÏÖ½ØÍ¼


ͼƬ2.png

½â¾ö¼Æ»®


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®


# ËùÓÐÓû§Ó¦Éý¼¶µ½ÆäÐû²¼ÏµÁÐÖÐ×îеIJ¹¶¡°æ±¾£º

npm install next@15.0.5   // for 15.0.x

npm install next@15.1.9   // for 15.1.x

npm install next@15.2.6   // for 15.2.x

npm install next@15.3.6   // for 15.3.x

npm install next@15.4.8   // for 15.4.x

npm install next@15.5.7   // for 15.5.x

npm install next@16.0.7   // for 16.0.x

# ÈôÊÇÄãʹÓõÄÊÇNext.js 14.3.0-canary.77 »ò¸ü¸ß°æ±¾µÄ canary °æ±¾£¬ £¬£¬£¬Çë½µ¼¶µ½×îеÄÎȹ̰æ 14.x£º


npm install next@14

# ¸ü¶àÐÅÏ¢Çë°Ý¼ûNext.js¸üÐÂÈÕÖ¾¡£¡£ ¡£¡£¡£¡£


¶þ¡¢ÄϹ¬NGÓéÀÖ½â¾ö¼Æ»®


1¡¢ÄϹ¬NGÓéÀÖ©ɨ²úÆ·¼Æ»®


Ìì¾µÎó²îɨÃèϵͳÒÑÓÚ2025-12-04ÉÏÏßCVE-2025-55182רÏî¼ì²âÄ£¿£¿£¿£¿é£º


×Ô¶¯Ê¶±ð RSC Í¨Ñ¶ÌØÕ÷

»ùÓÚÐÐÎªÖ¸ÎÆÅÐ¶Ï React/Next.js °æ±¾

·ÇÆÆËðÐÔÑéÖ¤£¬ £¬£¬£¬ÎÞÓªÒµÓ°Ïì

Ö§³Ö API Óë Web Ó¦ÓÃ×ʲúÅúÁ¿É¨Ãè


ɨÃèÕ½ÂÔ½¨Ò飺Îó²î¿âÉý¼¶ÖÁ×îа汾wvs_100ºóÏ·¢É¨ÃèʹÃü¡£¡£ ¡£¡£¡£¡£


ͼƬ3.png


2¡¢ÄϹ¬NGÓéÀÖ¼ì²âÀà²úÆ·¼Æ»®


¼ì²â²úÆ·ÍŶÓÒѸ´ÏÖ¸ÃÎó²î£¬ £¬£¬£¬¸÷¼ì²âϵͳÒÑÓÚ2025-12-04ÉÏÏßCVE-2025-55182רÏî¼ì²âÊÂÎñ¿â£º


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåWEBÇå¾²Ó¦ÓÃÍø¹Ø£¨WAF£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½×îа汾£¬ £¬£¬£¬¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦¡£¡£ ¡£¡£¡£¡£


ÊÂÎñ¿âÏÂÔØµØµã£º

https://venustech.download.venuscloud.cn/


3¡¢ÄϹ¬NGÓéÀÖ×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¼Æ»®


ÄϹ¬NGÓéÀÖ×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬ £¬£¬£¬React Server Components Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-55182£©, Çëʵʱ¶ÔÈë¿â×ʲú¾ÙÐÐÎó²îÖÎÀí¡£¡£ ¡£¡£¡£¡£ 


ͼƬ4.png


4¡¢ÄϹ¬NGÓéÀÖÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®


£¨1£©»ùÓÚ¹¥»÷ÐÐΪµÄ¹ØÁªÆÊÎöÕ½ÂÔ


Óû§¿ÉÒÔͨ¹ýÄϹ¬NGÓéÀÖÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬ £¬£¬£¬¾ÙÐйØÁªÆÊÎöÕ½ÂÔÉèÖ㬠£¬£¬£¬Á¬ÏµÏÖÕæÏàÐÎÖÐÊÕÂÞµÄϵͳÈÕÖ¾ºÍÇå¾²×°±¸¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬ £¬£¬£¬´Ó¶ø·¢Ã÷¡°React Server Components Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-55182)¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£¡£ ¡£¡£¡£¡£


ÔÚÌ©ºÏµÄƽ̨ÖУ¬ £¬£¬£¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°React Server Components Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-55182)¡±Îó²îɨÃèʹÃü£¬ £¬£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú¡£¡£ ¡£¡£¡£¡£


ͼƬ5.png


ƽ̨¡°¹ØÁªÆÊÎö¡±Ä£¿£¿£¿£¿éÖУ¬ £¬£¬£¬Ìí¼Ó¡°L2_React Server Components Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-55182)¡±£¬ £¬£¬£¬Í¨¹ýÄϹ¬NGÓéÀÖ¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬ £¬£¬£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ¡£¡£ ¡£¡£¡£¡£


ͼƬ6.png


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_React Server Components Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-55182)"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬ £¬£¬£¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓᣡ£ ¡£¡£¡£¡£


Ìí¼Ó¡°L3_React Server Components Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-55182)¡±£¬ £¬£¬£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_React Server Components Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-55182)¡±£¬ £¬£¬£¬¹¥»÷Ч¹û¼´ÊÇ»òÊôÓÚ¡°¹¥»÷Àֳɡ±£¬ £¬£¬£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬ £¬£¬£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶȡ£¡£ ¡£¡£¡£¡£


ͼƬ7.png


£¨2£©ATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé


ƾ֤¶ÔReact Server Components Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-55182)µÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö£¬ £¬£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒս׶Σ¬ £¬£¬£¬ÁýÕÖµÄTTP°üÀ¨£º


TA0001-³õʼ»á¼û£º T1190ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò

TA0004-ȨÏÞÌáÉý: T1055Àú³Ì×¢Èë

TA0009-Êý¾ÝÍøÂç: T1005´ÓÍâµØÏµÍ³ÍøÂçÊý¾Ý


ͼƬ8.png


ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦£¬ £¬£¬£¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾£¬ £¬£¬£¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£¡£ ¡£¡£¡£¡£


5¡¢ÄϹ¬NGÓéÀÖÖն˲úÆ·¼Æ»®


ÄϹ¬NGÓéÀÖÌì«‘ÖÕ¶ËÇå¾²Ò»Ì廯£¨EDR£©ÒѸ´ÏÖ¸ÃÎó²î£¬ £¬£¬£¬Ìṩ×Ô½ç˵poc£¬ £¬£¬£¬Æ¾Ö¤Àú³Ì¶¨Î»µ½ÏîÄ¿ËùÔÚÎļþ¼Ð»ñÈ¡node×é¼þ°æ±¾ÐÅÏ¢£¬ £¬£¬£¬¿É´ÓЧÀͶËÏ·¢poc¾ÙÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬ £¬£¬£¬Æ¥ÅäÎó²î×ʲú£¬ £¬£¬£¬Ô¤·ÀÎó²î¹¥»÷Σº¦¡£¡£ ¡£¡£¡£¡£



¹Ù·½Í¨¸æ£º

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components