React Server ComponentsÔ¶³Ì´úÂëÖ´Ðзì϶À´Ï®£¬OG¶«·½ÌüÌṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2025-12-04

½ñÈÕ£¬OG¶«·½Ìü¼à²âµ½Ò»¸ö´æÔÚÓÚReact Server ComponentsÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©,¸Ã·ì϶ÔÚ´¦Öÿͻ§¶Ë·¢Íù·þÎñ¶ËµÄ Flight ºÍ̸ÐòÁл¯¸ºÔØ£¨Payload£©Ê±£¬²»×ã¶Ô·´ÐòÁл¯¶ÔÏó½á¹¹µÄ°²È«Ð£Ñé»úÖÆ£¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâPayloadÒªÇó£¬Å²ÓÃNode.jsÄÚÖÃÄ£¿£¿é£¬´Ó¶øÔÚ·þÎñÆ÷É϶ñÒâÖ´ÐдúÂëºÍºÅÁµ¼Ö·þÎñÆ÷±»ÆëÈ«½ÚÖÆ¡£


·ì϶ÃèÊö


CVE-2025-55182 ÊÇÒ»¸ö´æÔÚÓÚ React Server Components£¨RSC£©ÊµÏÖÖеĸßΣԶ³Ì´úÂëÖ´ÐУ¨Remote Code Execution, RCE£©·ì϶£¬CVSS v3.1 ÆÀ·ÖΪ 10.0£¨Critical£©¡£

¸Ã·ì϶µÄµ××ÓÔ­ÒòÔÚÓÚReact¹Ù·½ÌṩµÄ·þÎñ¶ËÔËÐÐʱ°ü£¨Èç react-server¡¢¡¢react-server-dom-webpack»òreact-server-dom-parsing£©ÔÚ´¦Öÿͻ§¶Ë·¢Íù·þÎñ¶ËµÄFlight ºÍ̸ÐòÁл¯¸ºÔØ£¨Payload£©Ê±£¬²»×ã¶Ô·´ÐòÁл¯¶ÔÏó½á¹¹µÄ°²È«Ð£Ñé»úÖÆ¡£

´Ë·ì϶ӵÓÐÒÔϹؼüÌØµã£º

? ÎÞÐèÉí·ÝÈÏÖ¤£º¹¥»÷ÕßÖ»ÐèÄܽӼûRSC½Ó¿Ú£¨Í¨³£Îª¹«¿ªµÄ Web ·ÓÉ£©¼´¿É´¥·¢£»£»£»
ÀûÓÃÃż÷µÍ£º½öÐèÒ»´ÎHTTP POSTÒªÇ󣻣»£»
Ó°ÏìÁìÓò¹ã£ºËùÓÐʹÓùٷ½RSCʵÏֵĿò¼Ü£¨Èç Next.js¡¢¡¢Waku µÈ£©¾ùÊÜÓ°Ï죻£»£»
ÈÆ¹ýɳÏ䣺ִÐиߵÍÎÄΪ·þÎñ¶ËNode.js ¹ý³Ì£¬¿É¶ÁÈ¡»·¾³±äÁ¿¡¢¡¢Îļþϵͳ¡¢¡¢Êý¾Ý¿âÏνӵÈÃô¸Ð×ÊÔ´¡£


ͼƬ1.png


·ì϶¸´ÏÖ½ØÍ¼


ͼƬ2.png

½â¾ö¹æ»®


Ò»¡¢¡¢¹Ù·½ÐÞ¸´¹æ»®


# ËùÓÐЧ»§Ó¦Éý¼¶µ½Æä°ä²¼ÏµÁÐÖÐ×îеIJ¹¶¡°æ±¾£º

npm install next@15.0.5   // for 15.0.x

npm install next@15.1.9   // for 15.1.x

npm install next@15.2.6   // for 15.2.x

npm install next@15.3.6   // for 15.3.x

npm install next@15.4.8   // for 15.4.x

npm install next@15.5.7   // for 15.5.x

npm install next@16.0.7   // for 16.0.x

# ÈôÊÇÄãʹÓõÄÊÇNext.js 14.3.0-canary.77 »ò¸ü¸ß°æ±¾µÄ canary °æ±¾£¬Çë½µ¼¶µ½×îеIJ»±ä°æ 14.x£º


npm install next@14

# ¸ü¶àÐÅÏ¢Çë°Ý¼ûNext.js¸üÐÂÈÕÖ¾¡£


¶þ¡¢¡¢OG¶«·½Ìü½â¾ö¹æ»®


1¡¢¡¢OG¶«·½Ìü©ɨ²úÆ·¹æ»®


Ìì¾µ·ì϶ɨÃèϵͳÒÑÓÚ2025-12-04ÉÏÏßCVE-2025-55182רÏî¼ì²âÄ£¿£¿é£º


×Ô¶¯¼ø±ð RSC Í¨Ñ¶Ìصã

»ùÓÚÐÐÎªÖ¸ÎÆÅÐ¶Ï React/Next.js °æ±¾

·Ç·ÛËéÐÔÑéÖ¤£¬ÎÞÒµÎñÓ°Ïì

Ö§³Ö API Óë Web ÀûÓÃ×ʲúÅúÁ¿É¨Ãè


ɨÃèÕ½Êõ½¨Ò飺·ì϶¿âÉý¼¶ÖÁ×îа汾wvs_100ºóÏ·¢É¨Ã蹤×÷¡£


ͼƬ3.png


2¡¢¡¢OG¶«·½Ìü¼ì²âÀà²úÆ·¹æ»®


¼ì²â²úÆ·ÍŶÓÒѸ´Ïָ÷ì϶£¬¸÷¼ì²âϵͳÒÑÓÚ2025-12-04ÉÏÏßCVE-2025-55182רÏî¼ì²âÊÂÎñ¿â£º


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©¡¢¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢¡¢ÌìÇåWEB°²È«ÀûÓÃÍø¹Ø£¨WAF£©¡¢¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©Éý¼¶µ½×îа汾£¬¼´¿ÉÓÐЧ¼ì²â»ò·À»¤¸Ã·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ¡£


ÊÂÎñ¿âÏÂÔØµØÖ·£º

https://venustech.download.venuscloud.cn/


3¡¢¡¢OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®


OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©, Çëʵʱ¶ÔÈë¿â×ʲú½øÐзì϶ÖÎÀí¡£ 


ͼƬ4.png


4¡¢¡¢OG¶«·½Ìü°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®


£¨1£©»ùÓÚ¹¥»÷ÐÐΪµÄ¹ØÁª·ÖÎöÕ½Êõ


Óû§Äܹ»Í¨¹ýOG¶«·½ÌüÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬½øÐйØÁª·ÖÎöÕ½ÊõÅäÖ㬽áºÏÏÖʵ»·¾³Öвɼ¯µÄϵͳÈÕÖ¾ºÍ°²È«É豸¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£


ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡±·ì϶ɨÃ蹤×÷£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄÖØÒª×ʲú¡£


ͼƬ5.png


ƽ̨¡°¹ØÁª·ÖÎö¡±Ä£¿£¿éÖУ¬Ôö³¤¡°L2_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡±£¬Í¨¹ýOG¶«·½Ìü¼ì²âÉ豸¡¢¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ¡£


ͼƬ6.png


ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓá£


Ôö³¤¡°L3_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡±£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÈÓÚ»òÔ̺¬¡°L2_React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)¡±£¬¹¥»÷Á˾ֵÈÓÚ»òÊôÓÚ¡°¹¥»÷³É¹¦¡±£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶÈ¡£


ͼƬ7.png


£¨2£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé


ƾ¾Ý¶ÔReact Server Components Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2025-55182)µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬¸²¸ÇµÄTTPÔ̺¬£º


TA0001-³õʼ½Ó¼û£º T1190ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½

TA0004-ȨÏÞÌáÉý: T1055¹ý³Ì×¢Èë

TA0009-Êý¾ÝÍøÂç: T1005´Ó±¾µØÏµÍ³ÍøÂçÊý¾Ý


ͼƬ8.png


ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬½øÐÐ×Ô¶¯»¯´ëÖá£


5¡¢¡¢OG¶«·½ÌüÖն˲úÆ·¹æ»®


OG¶«·½ÌüÌì«‘Öն˰²È«Ò»Ì廯£¨EDR£©ÒѸ´Ïָ÷ì϶£¬Ìṩ×Ô½ç˵poc£¬Æ¾¾Ý¹ý³Ì¶¨Î»µ½ÏîÄ¿µØµãÎļþ¼Ð»ñÈ¡node×é¼þ°æ±¾ÐÅÏ¢£¬¿É´Ó·þÎñ¶ËÏ·¢poc½øÐÐÈ«ÍøÍ¬²½ÑéÖ¤£¬Æ¥Åä·ì϶×ʲú£¬Ô¤·À·ì϶¹¥»÷·çÏÕ¡£



¹Ù·½²¼¸æ£º

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components