Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

A POC for CVE-2025-55182

552,596 Aufrufe • vor 9 Monaten •via X (Twitter)

31 Kommentare

Profilbild von maple3142
maple3142vor 9 Monaten

It is like a fun node.js (or whatever server JS runtime) jail challenge that you would see in a CTF.

Profilbild von Peter Girnus 🦅
Peter Girnus 🦅vor 9 Monaten

CTF in prod. The best kind. The worst kind.

Profilbild von Tears
Tearsvor 9 Monaten

The original poc by Lachlan Davidson is available btw

Profilbild von thomas🌦
thomas🌦vor 9 Monaten

write-up someday of your technique?

Profilbild von maple3142
maple3142vor 9 Monaten

Just added a short writeup for the trick to the gist

Profilbild von thomas🌦
thomas🌦vor 9 Monaten

thank you!

Profilbild von Sylvie
Sylvievor 9 Monaten

ayyyyyyyy nice job <3

Profilbild von Basix
Basixvor 9 Monaten

clean and easy to understand, amazing!

Profilbild von MartinZugec
MartinZugecvor 9 Monaten

Heya, I see you're passing the child_process exploit string inside the _prefix property. How is this string being passed as an argument to the function? My understanding of the Flight protocol is that the parser doesn't automatically eval() strings in JSON values 🤔

Profilbild von Lexter
Lextervor 9 Monaten

good work I am working on that since the last night and I don't have found a good way to pollute to bypass proxy bundlerConfig. So big gg

Profilbild von Lucien
Lucienvor 9 Monaten

Insane poc ! gg

Profilbild von Ivan Garcia
Ivan Garciavor 9 Monaten

This is insane.

Profilbild von Jimmy
Jimmyvor 9 Monaten

what a gadget :O congrats! seems like first poc

Profilbild von IRIS C2
IRIS C2vor 9 Monaten

Good work

Profilbild von Chia
Chiavor 9 Monaten

It appears to work on a fresh created next project, but fails when a middleware (proxy.ts/middleware.ts) redirects unauthenticated users.

Profilbild von Y4GUAR3TE
Y4GUAR3TEvor 9 Monaten

@sushicomabacate

Profilbild von Turing@penligent.ai
[email protected]vor 9 Monaten

hi why not trying Penligent's one-click PoC? @penligent

Profilbild von ponti
pontivor 9 Monaten

Incredible work on the gadget chain, thanks for sharing

Profilbild von BENRICH
BENRICHvor 9 Monaten

Good stuff 👏

Profilbild von D.
D.vor 9 Monaten

😅

Profilbild von Alex
Alexvor 9 Monaten

Can you share the payload? Also a simple explanation of the _prefix thing 😀

Profilbild von Just_Clive
Just_Clivevor 9 Monaten

PoC is live. If you haven't patched yet, stop scrolling and run this: npx @neurolint/cli security:cve-2025-55182 . --fix Free. Open source. Takes 30 seconds.

Profilbild von Cyberexploit💀🧘
Cyberexploit💀🧘vor 9 Monaten

Noted

Profilbild von Night_Dive_C
Night_Dive_Cvor 9 Monaten

做得好👍

Profilbild von Gabriel Bigardi
Gabriel Bigardivor 9 Monaten

Thanks, i tried it today on my website, to my surprise it worked out, when i checked the /tmp/ it was full o xmrigs already... they are scanning the whole ip range

Profilbild von 🧊
🧊vor 9 Monaten

@h4x0r_dz How much vulnerable servers with this exploit out there?

Profilbild von CallMeWhy
CallMeWhyvor 9 Monaten

优雅

Profilbild von MissionPossible
MissionPossiblevor 9 Monaten

@grok о чем видео?

Profilbild von Hackers4Right- let us all weep
Hackers4Right- let us all weepvor 9 Monaten

any1 using this for sans?

Profilbild von ElleuchX1
ElleuchX1vor 9 Monaten

🐐

Profilbild von l2 p0ir3
l2 p0ir3vor 9 Monaten

To Explain & PoC

Ähnliche Videos