正在加载视频...

视频加载失败

A POC for CVE-2025-55182

552,596 次观看 • 9 个月前 •via X (Twitter)

31 条评论

maple3142 的头像
maple31429 个月前

It is like a fun node.js (or whatever server JS runtime) jail challenge that you would see in a CTF.

Peter Girnus 🦅 的头像
Peter Girnus 🦅9 个月前

CTF in prod. The best kind. The worst kind.

Tears 的头像
Tears9 个月前

The original poc by Lachlan Davidson is available btw

thomas🌦 的头像
thomas🌦9 个月前

write-up someday of your technique?

maple3142 的头像
maple31429 个月前

Just added a short writeup for the trick to the gist

thomas🌦 的头像
thomas🌦9 个月前

thank you!

Sylvie 的头像
Sylvie9 个月前

ayyyyyyyy nice job <3

Basix 的头像
Basix9 个月前

clean and easy to understand, amazing!

MartinZugec 的头像
MartinZugec9 个月前

Heya, I see you're passing the child_process exploit string inside the _prefix property. How is this string being passed as an argument to the function? My understanding of the Flight protocol is that the parser doesn't automatically eval() strings in JSON values 🤔

Lexter 的头像
Lexter9 个月前

good work I am working on that since the last night and I don't have found a good way to pollute to bypass proxy bundlerConfig. So big gg

Lucien 的头像
Lucien9 个月前

Insane poc ! gg

Ivan Garcia 的头像
Ivan Garcia9 个月前

This is insane.

Jimmy 的头像
Jimmy9 个月前

what a gadget :O congrats! seems like first poc

IRIS C2 的头像
IRIS C29 个月前

Good work

Chia 的头像
Chia9 个月前

It appears to work on a fresh created next project, but fails when a middleware (proxy.ts/middleware.ts) redirects unauthenticated users.

Y4GUAR3TE 的头像
Y4GUAR3TE9 个月前

@sushicomabacate

Turing@penligent.ai 的头像

hi why not trying Penligent's one-click PoC? @penligent

ponti 的头像
ponti9 个月前

Incredible work on the gadget chain, thanks for sharing

BENRICH 的头像
BENRICH9 个月前

Good stuff 👏

D. 的头像
D.9 个月前

😅

Alex 的头像
Alex9 个月前

Can you share the payload? Also a simple explanation of the _prefix thing 😀

Just_Clive 的头像
Just_Clive9 个月前

PoC is live. If you haven't patched yet, stop scrolling and run this: npx @neurolint/cli security:cve-2025-55182 . --fix Free. Open source. Takes 30 seconds.

Cyberexploit💀🧘 的头像
Cyberexploit💀🧘9 个月前

Noted

Night_Dive_C 的头像
Night_Dive_C9 个月前

做得好👍

Gabriel Bigardi 的头像
Gabriel Bigardi9 个月前

Thanks, i tried it today on my website, to my surprise it worked out, when i checked the /tmp/ it was full o xmrigs already... they are scanning the whole ip range

🧊 的头像
🧊9 个月前

@h4x0r_dz How much vulnerable servers with this exploit out there?

CallMeWhy 的头像
CallMeWhy9 个月前

优雅

MissionPossible 的头像
MissionPossible9 个月前

@grok о чем видео?

Hackers4Right- let us all weep 的头像
Hackers4Right- let us all weep9 个月前

any1 using this for sans?

ElleuchX1 的头像
ElleuchX19 个月前

🐐

l2 p0ir3 的头像
l2 p0ir39 个月前

To Explain & PoC

相关视频