<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE-2025-55182 on bokkapig</title><link>https://bokkapig.pages.dev/tags/cve-2025-55182/</link><description>Recent content in CVE-2025-55182 on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Tue, 04 Aug 2026 14:45:21 +0100</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/cve-2025-55182/index.xml" rel="self" type="application/rss+xml"/><item><title>Reactor</title><link>https://bokkapig.pages.dev/writeups/reactor/</link><pubDate>Tue, 04 Aug 2026 14:45:21 +0100</pubDate><guid>https://bokkapig.pages.dev/writeups/reactor/</guid><description>A ReactorWatch monitoring dashboard on port 3000 runs Next.js 15.0.3 with React 19.0.0 — vulnerable to React2Shell (CVE-2025-55182 / CVE-2025-66478), an unauthenticated RCE in the React Server Components Flight deserializer. A POST to / carrying a Next-Action header and a forged circular Flight chunk reaches Function via $1:constructor:constructor, giving code execution as the node service account. The app&amp;rsquo;s world-readable SQLite database yields engineer&amp;rsquo;s MD5 password hash, reused verbatim for SSH. Root comes from a root-owned uptime-monitor systemd unit launched with &amp;ndash;inspect=127.0.0.1:9229: the Node debug port is an unauthenticated root eval primitive, driven over the Chrome DevTools Protocol.</description></item></channel></rss>