Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | React Server Components Ô¶³Ì´úÂëÖ´Ðзì϶ |
CVE ID | CVE-2025-55182 |
·ì϶ÀàÐÍ | RCE | ·¢ÏÖ¹¦·ò | 2025-12-4 |
·ì϶ÆÀ·Ö | 10 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
ReactÊÇÒ»¸öÓÃÓÚ¹¹½¨Óû§½çÃæµÄJavaScript¿â£¬£¬£¬£¬£¬£¬£¬£¬ÓÉFacebook¿ª·¢ºÍÊØ»¤¡£¡£¡£¡£¡£Ëü»ùÓÚ×é¼þ»¯µÄ¿ª·¢Ä£Ê½£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÉêÃ÷ʽ±à³Ì¼ò»¯Á˽çÃæµÄ¹¹½¨ºÍ¸üС£¡£¡£¡£¡£Reactͨ¹ýÐé¹¹DOMÌáÉýäÖȾ»úÄÜ£¬£¬£¬£¬£¬£¬£¬£¬È·±£×îÓ×»¯¶ÔÕæÊµDOMµÄ²Ù×÷£¬£¬£¬£¬£¬£¬£¬£¬ÓÅ»¯ÁËÀûÓõÄÏìÓ¦ËÙ¶È¡£¡£¡£¡£¡£ËüÖ§³Öµ¥ÏòÊý¾ÝÁ÷£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýÁËÀûÓõĿÉÔ¤²âÐԺͿÉÊØ»¤ÐÔ¡£¡£¡£¡£¡£React¿ÉÓëÆäËû¿â»ò¿ò¼Üһ·ʹÓ㬣¬£¬£¬£¬£¬£¬£¬³£¼ûµÄ×éºÏÔ̺¬React RouterÓÃÓÚ·ÓÉÖÎÀíºÍReduxÓÃÓÚ״̬ÖÎÀí¡£¡£¡£¡£¡£ReactºÏÓÃÓÚ¹¹½¨ÏÖ´úWebºÍÒÆ¶¯¶ËÀûÓ㬣¬£¬£¬£¬£¬£¬£¬¿í·ºÀûÓÃÓÚǰ¶Ë¿ª·¢ÁìÓò¡£¡£¡£¡£¡£
2025Äê12ÔÂ4ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½Ò»¸ö´æÔÚÓÚReact Server ComponentsÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚReactÔÚ´¦Öÿͻ§¶Ë·¢Ë͵ÄÒªÇóʱ£¬£¬£¬£¬£¬£¬£¬£¬·´ÐòÁл¯»úÔì´æÔÚȱµã¡£¡£¡£¡£¡£React½«¿Í»§¶ËÒªÇóתΪHTTPÒªÇó²¢×ª·¢ÖÁ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Ö®ºóÔÚ·þÎñÆ÷¶Ë½«HTTPÒªÇó·´ÐòÁл¯Îªº¯ÊýŲÓᣡ£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâHTTPÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÀûÓø÷´ÐòÁл¯È±µã£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ·þÎñÆ÷¶ËÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐзçÏÕ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ×é¼þÔ̺¬react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopackµÈ¡£¡£¡£¡£¡£¸Ã·ì϶ÎÞÐèÈÏÖ¤¼´¿É±»¹¥»÷Õß´¥·¢£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܶÔϵͳ°²È«×é³ÉÑϳÁÍþв¡£¡£¡£¡£¡£
¶þ¡¢Ó°ÏìÁìÓò
react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.0react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.1.0react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.1.1react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.2.0
ÆäËûÊÜÓ°Ïì¿ò¼ÜºÍ´ò°ü·¨Ê½
React Router ²»²»±äµÄ RSC API °æ±¾Expo ËùÓÐÔ̺¬ react-server-dom-webpack°æ±¾Redwood SDK£ºrwsdk < 1.0.0-alpha.0Waku ËùÓÐÔ̺¬ react-server-dom-webpack°æ±¾@vitejs/plugin-rsc ËùÓÐʹÓò»°²È«°æ±¾µÄ²å¼þ
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£npm install next@15.0.5 £¨ºÏÓÃÓÚ 15.0.x£©npm install next@15.1.9 £¨ºÏÓÃÓÚ 15.1.x£©npm install next@15.2.6 £¨ºÏÓÃÓÚ 15.2.x£©npm install next@15.3.6 £¨ºÏÓÃÓÚ 15.3.x£©npm install next@15.4.8 £¨ºÏÓÃÓÚ 15.4.x£©npm install next@15.5.7 £¨ºÏÓÃÓÚ 15.5.x£©npm install next@16.0.7 £¨ºÏÓÃÓÚ 16.0.x£©ÈôÊÇʹÓà Next.js 14.3.0-canary.77 »ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬Çë½µ¼¶µ½×îеIJ»±ä 14.x °æ±¾£ºÈôÊÇʹÓà React Router µÄ²»²»±ä RSC API£¬£¬£¬£¬£¬£¬£¬£¬Éý¼¶ÒÔÏÂÒÀÀµ£ºnpm install react-dom@latestnpm install react-server-dom-parcel@latestnpm install react-server-dom-webpack@latestnpm install @vitejs/plugin-rsc@latestÉý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£ºnpm install react@latest react-dom@latest react-server-dom-webpack@latestÈ·±£°æ±¾Îª rwsdk >= 1.0.0-alpha.0Éý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£ºnpm install react@latest react-dom@latest react-server-dom-webpack@latestÉý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£ºnpm install react@latest react-dom@latest react-server-dom-webpack@latestÉý¼¶ÖÁ×îа汾µÄ RSC ²å¼þ£ºnpm install react@latest react-dom@latest @vitejs/plugin-rsc@latestnpm install react@latest react-dom@latest react-server-dom-parcel@latestreact-server-dom-turbopacknpm install react@latest react-dom@latest react-server-dom-turbopack@latestnpm install react@latest react-dom@latest react-server-dom-webpack@latest
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£? ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬£¬£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬£¬£¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬£¬£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£? ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components/https://www.cve.org/CVERecord?id=CVE-2025-55182