Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

A POC for CVE-2025-55182

552,596 görüntüleme • 9 ay önce •via X (Twitter)

31 Yorum

maple3142 profil fotoğrafı
maple31429 ay önce

It is like a fun node.js (or whatever server JS runtime) jail challenge that you would see in a CTF.

Peter Girnus 🦅 profil fotoğrafı
Peter Girnus 🦅9 ay önce

CTF in prod. The best kind. The worst kind.

Tears profil fotoğrafı
Tears9 ay önce

The original poc by Lachlan Davidson is available btw

thomas🌦 profil fotoğrafı
thomas🌦9 ay önce

write-up someday of your technique?

maple3142 profil fotoğrafı
maple31429 ay önce

Just added a short writeup for the trick to the gist

thomas🌦 profil fotoğrafı
thomas🌦9 ay önce

thank you!

Sylvie profil fotoğrafı
Sylvie9 ay önce

ayyyyyyyy nice job <3

Basix profil fotoğrafı
Basix9 ay önce

clean and easy to understand, amazing!

MartinZugec profil fotoğrafı
MartinZugec9 ay önce

Heya, I see you're passing the child_process exploit string inside the _prefix property. How is this string being passed as an argument to the function? My understanding of the Flight protocol is that the parser doesn't automatically eval() strings in JSON values 🤔

Lexter profil fotoğrafı
Lexter9 ay önce

good work I am working on that since the last night and I don't have found a good way to pollute to bypass proxy bundlerConfig. So big gg

Lucien profil fotoğrafı
Lucien9 ay önce

Insane poc ! gg

Ivan Garcia profil fotoğrafı
Ivan Garcia9 ay önce

This is insane.

Jimmy profil fotoğrafı
Jimmy9 ay önce

what a gadget :O congrats! seems like first poc

IRIS C2 profil fotoğrafı
IRIS C29 ay önce

Good work

Chia profil fotoğrafı
Chia9 ay önce

It appears to work on a fresh created next project, but fails when a middleware (proxy.ts/middleware.ts) redirects unauthenticated users.

Y4GUAR3TE profil fotoğrafı
Y4GUAR3TE9 ay önce

@sushicomabacate

Turing@penligent.ai profil fotoğrafı

hi why not trying Penligent's one-click PoC? @penligent

ponti profil fotoğrafı
ponti9 ay önce

Incredible work on the gadget chain, thanks for sharing

BENRICH profil fotoğrafı
BENRICH9 ay önce

Good stuff 👏

D. profil fotoğrafı
D.9 ay önce

😅

Alex profil fotoğrafı
Alex9 ay önce

Can you share the payload? Also a simple explanation of the _prefix thing 😀

Just_Clive profil fotoğrafı
Just_Clive9 ay önce

PoC is live. If you haven't patched yet, stop scrolling and run this: npx @neurolint/cli security:cve-2025-55182 . --fix Free. Open source. Takes 30 seconds.

Cyberexploit💀🧘 profil fotoğrafı
Cyberexploit💀🧘9 ay önce

Noted

Night_Dive_C profil fotoğrafı
Night_Dive_C9 ay önce

做得好👍

Gabriel Bigardi profil fotoğrafı
Gabriel Bigardi9 ay önce

Thanks, i tried it today on my website, to my surprise it worked out, when i checked the /tmp/ it was full o xmrigs already... they are scanning the whole ip range

🧊 profil fotoğrafı
🧊9 ay önce

@h4x0r_dz How much vulnerable servers with this exploit out there?

CallMeWhy profil fotoğrafı
CallMeWhy9 ay önce

优雅

MissionPossible profil fotoğrafı
MissionPossible9 ay önce

@grok о чем видео?

Hackers4Right- let us all weep profil fotoğrafı
Hackers4Right- let us all weep9 ay önce

any1 using this for sans?

ElleuchX1 profil fotoğrafı
ElleuchX19 ay önce

🐐

l2 p0ir3 profil fotoğrafı
l2 p0ir39 ay önce

To Explain & PoC

Benzer Videolar