GA»Æ½ð¼×

¡°¼«¼ò¡±»ÀР¡¤ È«ÓòÖÇÁª Ø­ GA»Æ½ð¼×м«¼òÁ캽ÏÂÒ»´úÐ£Ô°Íø½¨Éè×êÑлá
date
Ô¤Ô¼Ö±²¥
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨°ä²¼
date
Ô¤Ô¼Ö±²¥
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¹æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¹æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷ͬ°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/˵»°
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×°²È«¹ØÓÚ¼«Î£React Server ComponentsÔ¶³Ì´úÂëÖ´Ðзì϶µÄ½â¶Á

½üÆÚ£¬React ÍŶÓÅû¶ÁËReact Server Components×é¼þÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©¡£React ·þÎñÆ÷×é¼þ£¨RSC£©ÊÇÒ»ÏîÖ÷ÌâÖ°ÄÜ£¬ËüÔÊÐí¿ª·¢ÕßÔÚ·þÎñÆ÷¶ËÖ±½ÓäÖȾ×é¼þ£¬²¢½«Á˾ַ¢ËÍÖÁ¿Í»§¶Ë£¬´Ó¶øÌáÉý»úÄÜÓëÓû§ÂÄÀú¡£Ä¿Ç°£¬¸Ã¼¼ÊõÒѱ»Next.js¡¢Shopify Hydrogen¡¢Gatsby 5µÈÖ÷Á÷¿ò¼Ü¿í·ºÑ¡È¡£¬ÔÚµçÉÌÆ½Ì¨¡¢SaaS·þÎñÒÔ¼°ÄÚÈÝÕ¾µãµÈ¶à¸öÁìÓòÓµÓÐÆÕ±éÀûÓá£ÔÚFOFA×ʲú²â»æÆ½Ì¨µÄ¼à²âÊý¾ÝÖУ¬GA»Æ½ð¼×°²È«·¢ÏÖ»ùÓÚNext.jsµÄÀûÓÃ×ʲúÊýÁ¿ÒÑ´ï766Íò£¬ÕâÒâζ×ų¬¹ý200Íǫ̀·þÎñÆ÷¿ÉÄÜÃæ¶Ô°²È«·çÏÕ¡£ÓÈΪÑϸñµÄÊÇ£¬Óйطì϶µÄÀûÓóɹ¦Âʼ«¸ß£¬¿¿½ü100%£¬¹¥»÷Õß¿ÉÄܲ»±äʵÏÖÆëÈ«µÄÔ¶³Ì´úÂëÖ´ÐУ¬¶Ôϵͳ°²È«×é³ÉÑϳÁÍþв¡£

  • GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

    °ä²¼¹¦·ò£º2026-01-05

  • GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

    µã»÷Á¿£º

  • GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

    µãÔÞ£º

·ÖÏíÖÁ

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ÎÒÏëÆÀÂÛ

½üÆÚ£¬React ÍŶÓÅû¶ÁËReact Server Components×é¼þÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2025-55182£©¡£React ·þÎñÆ÷×é¼þ£¨RSC£©ÊÇÒ»ÏîÖ÷ÌâÖ°ÄÜ£¬ËüÔÊÐí¿ª·¢ÕßÔÚ·þÎñÆ÷¶ËÖ±½ÓäÖȾ×é¼þ£¬²¢½«Á˾ַ¢ËÍÖÁ¿Í»§¶Ë£¬´Ó¶øÌáÉý»úÄÜÓëÓû§ÂÄÀú¡£Ä¿Ç°£¬¸Ã¼¼ÊõÒѱ»Next.js¡¢Shopify Hydrogen¡¢Gatsby 5µÈÖ÷Á÷¿ò¼Ü¿í·ºÑ¡È¡£¬ÔÚµçÉÌÆ½Ì¨¡¢SaaS·þÎñÒÔ¼°ÄÚÈÝÕ¾µãµÈ¶à¸öÁìÓòÓµÓÐÆÕ±éÀûÓá£

ÔÚFOFA×ʲú²â»æÆ½Ì¨µÄ¼à²âÊý¾ÝÖУ¬GA»Æ½ð¼×°²È«·¢ÏÖ»ùÓÚNext.jsµÄÀûÓÃ×ʲúÊýÁ¿ÒÑ´ï766Íò£¬ÕâÒâζ×ų¬¹ý200Íǫ̀·þÎñÆ÷¿ÉÄÜÃæ¶Ô°²È«·çÏÕ¡£ÓÈΪÑϸñµÄÊÇ£¬Óйطì϶µÄÀûÓóɹ¦Âʼ«¸ß£¬¿¿½ü100%£¬¹¥»÷Õß¿ÉÄܲ»±äʵÏÖÆëÈ«µÄÔ¶³Ì´úÂëÖ´ÐУ¬¶Ôϵͳ°²È«×é³ÉÑϳÁÍþв¡£

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

1.·ì϶¸ÅÊö

·ì϶±àºÅ£ºCVE-2025-55182

·ì϶ÀàÐÍ£ºÔ¶³Ì´úÂëÖ´ÐÐ(RCE)

·ì϶µÈ¼¶£º¸ßΣ

Ó°ÏìÁìÓò£ºReact Server Components Óйؿò¼ÜºÍ¿â£¬ÀýÈçNext.jsµÈ¡£

·¢ÏÖ¹¦·ò£º2025Äê12ÔÂ3ÈÕ

CVSSÆÀ·Ö£º10£¨ÆÀ·ÖÁìÓò1-10£¬¸Ã·ì϶ÆÀ·Ö×î¸ß£©

POC״̬£ºÒѹ«¿ª

1.1 ·ì϶ӰÏì°æ°æ±¾

Èí¼þ°ü ÊÜÓ°Ïì°æ¼¼ÇÉÓò
Next.js 15.0.0 -15.0.4
15.1.0 -15.1.8
15.2.0 -15.2.5
15.3.0 -15.3.5
15.4.0 -15.4.7
16.0.0 -16.0.6
React RSC 19.0.0
19.1.0 -19.1.1

  

1.2 ·ì϶¸´ÏÖ

·¢Ë͹«¿ªµÄHTTP¶ñÒâÒªÇóPayloadÄܹ»¿´µ½·þÎñÆ÷³É¹¦Ö´ÐÐÎÒÃÇÒªÇóÖ´ÐÐwhoamiºÅÁ·þÎñÆ÷³É¹¦Ö´ÐÐwhoami²¢ÔÚÏìÓ¦Öзµ»ØwhoamiºÅÁîÖ´ÐеÄÁ˾Ö¡£

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

2.·ì϶µÀÀí·ÖÎö

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

FlightºÍ̸£º

React 19ÒýÈëµÄ¿Í»§¶Ë-·þÎñ¶ËͨѶºÍ̸

ʹÓÃÌØÊâµÄÐòÁл¯Ìåʽ´«ÊäReact×é¼þÊ÷

Ö§³ÖÒýÓÃϵͳ£º$@N (chunkÒýÓÃ), $B N (BlobÒýÓÃ), $F N (º¯ÊýÒýÓÃ)

·þÎñ¶Ë·´ÐòÁл¯ºóÖ´ÐÐServer Actions/Components

CVE-2025-55182·ì϶ÊÇÔ´ÓÚ·þÎñ¶ËÔÚ·´ÐòÁл¯ Server Action ÒªÇóʱδУÑéÄ£¿éµ¼³öÊôÐԵĺϷ¨ÐÔ£¬¹¥»÷Õß¿Éͨ¹ý²Ù¿ØÒªÇó¸ºÔؽӼûÔ­ÐÍÁ´ÉϵÄΣÏÕ²½Ö裨Èç vm.runInThisContext£©£¬½ø¶øÖ´ÐÐËÁÒâϵͳºÅÁֻÓÐÀûÓÃÒÀÀµÖÐÔ̺¬ vm¡¢child_process »ò fs µÈ³£¼û Node.js Ä£¿é¼´¿É±»ÀûÓ㬹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâRSCÒªÇóÔÚ·þÎñÆ÷¶ËʵÏÖËÁÒâ´úÂëÖ´ÐС£

3.½¨¸´¹æ»®

3.1 ¹Ù·½½¨¸´¹æ»®

½¨¸´½â¾ö¹æ»®£¨º¬·ì϶²¹¶¡£©£º

¹Ù·½ÒѰ䲼°²È«²¹¶¡£¬Çëʵʱ¸üÐÂÖÁ×îа汾£ºReact Server 19.0.1¡¢React Server 19.1.2¡¢React Server 19.2.1

ÏÂÔØµØÖ·£ºhttps://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

»òÕßͨ¹ýºÅÁîÉý¼¶µ½°²È«°æ±¾£¬npm install react@19.0.1 react-dom@19.0.1 next@15.0.5

3.2 GA»Æ½ð¼×·À»ðǽ·À»¤¹æ»®

GA»Æ½ð¼×ÍøÂç·À»ðǽÔÚÍøÂçÌìǵ¾«×¼¹ýÂËЯ´øCVE-2025-55182·ì϶¹¥»÷ÌØµãµÄ¶ñÒâÁ÷Á¿£¬Í¨¹ýͨÓÃÐÍ·ì϶+¾ßÌå·ì϶µÄ¼ì²âÀíÏ룬ʵÏÖ¶Ôδ֪+ÒÑÖª·ì϶µÄ¾«×¼À¹½ØºÍ×è¶Ï£¬WEBÀûÓð²È«Í¨¹ýÉî¶È½âÎöHTTPÒªÇó±¨ÎÄ£¬¾«×¼¼ø±ðÈçŲÓÃchild_process.execSyncµÄ¸ßΣ²ÎÊý¼°¶ñÒâ»ú¹ØÄÚÈÝ£¬ÖþÀÎWeb²ã×ÝÉî·ÀÓù·®Àé¡£

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

1.Éý¼¶·À»ðǽµÄIPS¹æ¶¨¿â°æ±¾µ½v20251208.1421°æ±¾

ÑéÖ¤¹æ¶¨13240144¡¢13240145¡¢13240146ÊÇ·ñÔڹ涨¿â¡£ÔÚϵͳ--ÌØµã¿âÉý¼¶Ä£¿é¿ªÆô×Ô¶¯Éý¼¶ºó£¬Ìصã¿â½«»á×Ô¶¯ÁªÍø¸üУ¬×Ô¶¯¸üÐÂÌØµã¿âµÄÉ豸²»Êܸ÷ì϶ӰÏì¡£

2.δÁªÍøÉ豸Äܹ»Í¨¹ýµÇ¼GA»Æ½ð¼×°²È«ÔƹÙÍøhttps://secloud1.ruijie.com.cn/login£¬ÏÂÔØ×îеÄIPS¹æ¶¨¿â

±£Õϰ汾ÔÚv20251208.1421ÒÔÉÏ£¬ÀëÏßÉý¼¶¹æ¶¨¿â¡£

»ùÓÚÒÔÉÏ·ÖÎö£¬Õë¶ÔReact CVE-2025-55182ÕâÒ»CVSSÂú·Ö¸ßΣ·ì϶£¬GA»Æ½ð¼×·À»ðǽµÄÖ÷Ìâ·À»¤ÓÅÊÆ¿É¸ÅÀ¨Îª“¿ì¡¢È«¡¢¼ò”Èý´óÌØµã£º

ÏìӦѸ¿ì£º·ì϶Åû¶ºó24Ó×ʱÄÚ¼´ÊµÏÖ¹¥»÷ÌØµãÌáÈ¡Óë·À»¤¹æ¶¨Í¬²½£¬Ô®ÊÖÓû§ÔÚµÚÒ»¹¦·òÆô¶¯ÓÐЧ·ÀÓù£»

¸²¸ÇÈ«Ãæ£ºÌṩÕë¶ÔÐÔ·À»¤¹æ¶¨£¬¼´¿ª¼´Óã¬ÎÞÐ踴ÔÓÅäÖã»

²¿ÊðÇá±ã£º¼´±ãÔÝδʵÏÖϵͳ²¹¶¡Éý¼¶£¬Óû§Ò²¿Éͨ¹ýÒ»¼üÆôÓù涨£¬¼±¾ç¹¹½¨°²È«»º³åµØ´ø¡£

ÓйرêÇ©£º

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

µãÔÞ

¸ü¶à¼¼Êõ²©ÎÄ

ÈκαØÒª£¬ÇëÁªÏµGA»Æ½ð¼×

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµAI¸±ÊÖ
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµÆÀ¼Û
ev-close
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
ev-close
Äú¶Ôµ±Ç°Ò³ÃæµÄÖÐÒâ¶ÈÈôºÎ£¿
²»Õ¦µÎ
¼«¶ÈºÃ
dark-star dark-star dark-star dark-star dark-star
ev-close
ÄúÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
ev-close
Äú²»ÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
ev-close
ÄúÊÇ·ñ»¹ÓÐÆäËûÎÊÌâ»ò½¨Ò飿
ΪÁ˼±¾ç½â¾ö²¢»Ø¸´ÄúµÄÎÊÌ⣬ÄúÄܹ»ÁôÏÂÁªÏµ·½Ê½
ÓÊÏä
ÊÖ»úºÅ
ev-bg
¸Ð¼¤ÄúµÄ·´À¡£¡
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø¹ØÕ÷ѯҳ
ÊÛǰÕ÷ѯ ÊÛǰÕ÷ѯ
ÊÛǰÕ÷ѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
¶¨¼û·´À¡ ¶¨¼û·´À¡
¶¨¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿