97¹ú¼Ê

Àë±ðÔËάÄÚÚ§ È«ÓòЭͬÌáЧ Ø­ 97¹ú¼ÊÍøÂçÔËά°ü¹ÜÂÄÀú·ÖÏí»á
Ô¤Ô¼Ö±²¥
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨Ðû²¼
Ô¤Ô¼Ö±²¥
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¼Æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¼Æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼ÊÇå¾²¹ØÓÚ¼«Î£React Server ComponentsÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ½â¶Á

½üÆÚ£¬React ÍŶÓÅû¶ÁËReact Server Components×é¼þÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-55182£©¡£React ·þÎñÆ÷×é¼þ£¨RSC£©ÊÇÒ»Ïî½¹µã¹¦Ð§£¬ËüÔÊÐí¿ª·¢ÕßÔÚ·þÎñÆ÷¶ËÖ±½ÓäÖȾ×é¼þ£¬²¢½«Ð§¹û·¢ËÍÖÁ¿Í»§¶Ë£¬´Ó¶øÌáÉýÐÔÄÜÓëÓû§ÌåÑé¡£ÏÖÔÚ£¬¸ÃÊÖÒÕÒѱ»Next.js¡¢Shopify Hydrogen¡¢Gatsby 5µÈÖ÷Á÷¿ò¼ÜÆÕ±é½ÓÄÉ£¬ÔÚµçÉÌÆ½Ì¨¡¢SaaS·þÎñÒÔ¼°ÄÚÈÝÕ¾µãµÈ¶à¸öÁìÓò¾ßÓÐÆÕ±éÓ¦Óá£ÔÚFOFA×ʲú²â»æÆ½Ì¨µÄ¼à²âÊý¾ÝÖУ¬97¹ú¼ÊÇå¾²·¢Ã÷»ùÓÚNext.jsµÄÓ¦ÓÃ×ʲúÊýÄ¿ÒÑ´ï766Íò£¬ÕâÒâζ×ÅÁè¼Ý200Íǫ̀·þÎñÆ÷¿ÉÄÜÃæÁÙÇ徲Σº¦¡£ÓÈΪÑÏËàµÄÊÇ£¬Ïà¹ØÎó²îµÄʹÓÃÀÖ³ÉÂʼ«¸ß£¬¿¿½ü100%£¬¹¥»÷ÕßÄܹ»ÎȹÌʵÏÖÍêÕûµÄÔ¶³Ì´úÂëÖ´ÐУ¬¶ÔϵͳÇå¾²×é³ÉÑÏÖØÍþв¡£

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    Ðû²¼Ê±¼ä£º2026-01-05

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    µã»÷Á¿£º

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    µãÔÞ£º

·ÖÏíÖÁ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ÎÒÏë̸ÂÛ

½üÆÚ£¬React ÍŶÓÅû¶ÁËReact Server Components×é¼þÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2025-55182£©¡£React ·þÎñÆ÷×é¼þ£¨RSC£©ÊÇÒ»Ïî½¹µã¹¦Ð§£¬ËüÔÊÐí¿ª·¢ÕßÔÚ·þÎñÆ÷¶ËÖ±½ÓäÖȾ×é¼þ£¬²¢½«Ð§¹û·¢ËÍÖÁ¿Í»§¶Ë£¬´Ó¶øÌáÉýÐÔÄÜÓëÓû§ÌåÑé¡£ÏÖÔÚ£¬¸ÃÊÖÒÕÒѱ»Next.js¡¢Shopify Hydrogen¡¢Gatsby 5µÈÖ÷Á÷¿ò¼ÜÆÕ±é½ÓÄÉ£¬ÔÚµçÉÌÆ½Ì¨¡¢SaaS·þÎñÒÔ¼°ÄÚÈÝÕ¾µãµÈ¶à¸öÁìÓò¾ßÓÐÆÕ±éÓ¦Óá£

ÔÚFOFA×ʲú²â»æÆ½Ì¨µÄ¼à²âÊý¾ÝÖУ¬97¹ú¼ÊÇå¾²·¢Ã÷»ùÓÚNext.jsµÄÓ¦ÓÃ×ʲúÊýÄ¿ÒÑ´ï766Íò£¬ÕâÒâζ×ÅÁè¼Ý200Íǫ̀·þÎñÆ÷¿ÉÄÜÃæÁÙÇ徲Σº¦¡£ÓÈΪÑÏËàµÄÊÇ£¬Ïà¹ØÎó²îµÄʹÓÃÀÖ³ÉÂʼ«¸ß£¬¿¿½ü100%£¬¹¥»÷ÕßÄܹ»ÎȹÌʵÏÖÍêÕûµÄÔ¶³Ì´úÂëÖ´ÐУ¬¶ÔϵͳÇå¾²×é³ÉÑÏÖØÍþв¡£

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

1.Îó²î¸ÅÊö

Îó²î±àºÅ£ºCVE-2025-55182

Îó²îÀàÐÍ£ºÔ¶³Ì´úÂëÖ´ÐÐ(RCE)

Îó²îÆ·¼¶£º¸ßΣ

Ó°Ïì¹æÄ££ºReact Server Components Ïà¹Ø¿ò¼ÜºÍ¿â£¬ÀýÈçNext.jsµÈ¡£

·¢Ã÷ʱ¼ä£º2025Äê12ÔÂ3ÈÕ

CVSSÆÀ·Ö£º10£¨ÆÀ·Ö¹æÄ£1-10£¬¸ÃÎó²îÆÀ·Ö×î¸ß£©

POC״̬£ºÒѹûÕæ

1.1 Îó²îÓ°Ïì°æ°æ±¾

Èí¼þ°ü ÊÜÓ°Ïì°æ±¾¹æÄ£
Next.js 15.0.0 -15.0.4
15.1.0 -15.1.8
15.2.0 -15.2.5
15.3.0 -15.3.5
15.4.0 -15.4.7
16.0.0 -16.0.6
React RSC 19.0.0
19.1.0 -19.1.1

  

1.2 Îó²î¸´ÏÖ

·¢Ë͹ûÕæµÄHTTP¶ñÒâÇëÇóPayload¿ÉÒÔ¿´µ½·þÎñÆ÷ÀÖ³ÉÖ´ÐÐÎÒÃÇÒªÇóÖ´ÐÐwhoamiÏÂÁ·þÎñÆ÷ÀÖ³ÉÖ´ÐÐwhoami²¢ÔÚÏìÓ¦Öзµ»ØwhoamiÏÂÁîÖ´ÐеÄЧ¹û¡£

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

2.Îó²îÔ­ÀíÆÊÎö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

FlightЭÒ飺

React 19ÒýÈëµÄ¿Í»§¶Ë-·þÎñ¶ËͨѶЭÒé

ʹÓÃÌØÊâµÄÐòÁл¯ÃûÌô«ÊäReact×é¼þÊ÷

Ö§³ÖÒýÓÃϵͳ£º$@N (chunkÒýÓÃ), $B N (BlobÒýÓÃ), $F N (º¯ÊýÒýÓÃ)

·þÎñ¶Ë·´ÐòÁл¯ºóÖ´ÐÐServer Actions/Components

CVE-2025-55182Îó²îÊÇÔ´ÓÚ·þÎñ¶ËÔÚ·´ÐòÁл¯ Server Action ÇëÇóʱδУÑéÄ£¿éµ¼³öÊôÐÔµÄÕýµ±ÐÔ£¬¹¥»÷Õß¿Éͨ¹ý²Ù¿ØÇëÇó¸ºÔØ»á¼ûÔ­ÐÍÁ´ÉϵÄΣÏÕÒªÁ죨Èç vm.runInThisContext£©£¬½ø¶øÖ´ÐÐí§ÒâϵͳÏÂÁֻҪӦÓÃÒÀÀµÖаüÀ¨ vm¡¢child_process »ò fs µÈ³£¼û Node.js Ä£¿é¼´¿É±»Ê¹Ó㬹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâRSCÇëÇóÔÚ·þÎñÆ÷¶ËʵÏÖí§Òâ´úÂëÖ´ÐС£

3.ÐÞ¸´¼Æ»®

3.1 ¹Ù·½ÐÞ¸´¼Æ»®

ÐÞ¸´½â¾ö¼Æ»®£¨º¬Îó²î²¹¶¡£©£º

¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡£¬Çëʵʱ¸üÐÂÖÁ×îа汾£ºReact Server 19.0.1¡¢React Server 19.1.2¡¢React Server 19.2.1

ÏÂÔØµØÖ·£ºhttps://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

»òÕßͨ¹ýÏÂÁîÉý¼¶µ½Çå¾²°æ±¾£¬npm install react@19.0.1 react-dom@19.0.1 next@15.0.5

3.2 97¹ú¼Ê·À»ðǽ·À»¤¼Æ»®

97¹ú¼ÊÍøÂç·À»ðǽÔÚÍøÂç½çÏß¾«×¼¹ýÂËЯ´øCVE-2025-55182Îó²î¹¥»÷ÌØÕ÷µÄ¶ñÒâÁ÷Á¿£¬Í¨¹ýͨÓÃÐÍÎó²î+ÏêϸÎó²îµÄ¼ì²âÀíÄʵÏÖ¶Ôδ֪+ÒÑÖªÎó²îµÄ¾«×¼×èµ²ºÍ×è¶Ï£¬WEBÓ¦ÓÃÇ徲ͨ¹ýÉî¶ÈÆÊÎöHTTPÇëÇó±¨ÎÄ£¬¾«×¼Ê¶±ðÈçŲÓÃchild_process.execSyncµÄ¸ßΣ²ÎÊý¼°¶ñÒâ½á¹¹ÄÚÈÝ£¬ÖþÀÎWeb²ã×ÝÉî·ÀÓùÆÁÕÏ¡£

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

1.Éý¼¶·À»ðǽµÄIPS¹æÔò¿â°æ±¾µ½v20251208.1421°æ±¾

ÑéÖ¤¹æÔò13240144¡¢13240145¡¢13240146ÊÇ·ñÔÚ¹æÔò¿â¡£ÔÚϵͳ--ÌØÕ÷¿âÉý¼¶Ä£¿é¿ªÆô×Ô¶¯Éý¼¶ºó£¬ÌØÕ÷¿â½«»á×Ô¶¯ÁªÍø¸üУ¬×Ô¶¯¸üÐÂÌØÕ÷¿âµÄ×°±¸²»ÊܸÃÎó²îÓ°Ïì¡£

2.δÁªÍø×°±¸¿ÉÒÔͨ¹ýµÇ¼97¹ú¼ÊÇå¾²ÔÆ¹ÙÍøhttps://secloud1.ruijie.com.cn/login£¬ÏÂÔØ×îеÄIPS¹æÔò¿â

°ü¹Ü°æ±¾ÔÚv20251208.1421ÒÔÉÏ£¬ÀëÏßÉý¼¶¹æÔò¿â¡£

»ùÓÚÒÔÉÏÆÊÎö£¬Õë¶ÔReact CVE-2025-55182ÕâÒ»CVSSÂú·Ö¸ßΣÎó²î£¬97¹ú¼Ê·À»ðǽµÄ½¹µã·À»¤ÓÅÊÆ¿É¹éÄÉ×ÛºÏΪ“¿ì¡¢È«¡¢¼ò”Èý´óÌØµã£º

ÏìӦѸËÙ£ºÎó²îÅû¶ºó24СʱÄÚ¼´Íê³É¹¥»÷ÌØÕ÷ÌáÈ¡Óë·À»¤¹æÔòͬ²½£¬×ÊÖúÓû§ÔÚµÚһʱ¼äÆô¶¯ÓÐÓ÷ÀÓù £»

ÁýÕÖÖÜÈ«£ºÌṩÕë¶ÔÐÔ·À»¤¹æÔò£¬¼´¿ª¼´Óã¬ÎÞÐèÖØ´óÉèÖà £»

°²ÅÅÇáÓ¯£º×ÝÈ»ÔÝδÍê³Éϵͳ²¹¶¡Éý¼¶£¬Óû§Ò²¿Éͨ¹ýÒ»¼üÆôÓùæÔò£¬¿ìËÙ¹¹½¨Çå¾²»º³åµØ´ø¡£

Ïà¹Ø±êÇ©£º

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

µãÔÞ

¸ü¶àÊÖÒÕ²©ÎÄ

ÈκÎÐèÒª£¬ÇëÁªÏµ97¹ú¼Ê

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ ÎĵµAIÖúÊÖ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
Äú¶ÔÄ¿½ñÒ³ÃæµÄÖª×ã¶ÈÔõÑù£¿
²»Õ¦µÎ
ºÜÊǺÃ
ÄúÖª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£©£¿
Äú²»Öª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£©£¿
ÄúÊÇ·ñÉÐÓÐÆäËûÎÊÌâ»ò½¨Ò飿
ΪÁË¿ìËÙ½â¾ö²¢»Ø¸´ÄúµÄÎÊÌ⣬Äú¿ÉÒÔÁôÏÂÁªÏµ·½·¨
ÓÊÏä
ÊÖ»úºÅ
ллÄúµÄ·´À¡£¡
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´Ïì Òâ¼û·´Ïì
Òâ¼û·´Ïì
¸ü¶àÁªÏµ·½·¨
ÍøÕ¾µØÍ¼