运行 nextjs-nextjs--CVE-2025-49005-20260318035740

漏洞条目
nextjs--CVE-2025-49005
实证状态
verified-real
复现 Profile
nextjs-proxy-boundary
Artifact 模式
local-fixture

Mermaid 时间线

flowchart LR
A["选择 Advisory"] --> B["解析 Repro Profile"]
B --> C["生成 Compose 环境"]
C --> D["采集基线快照"]
D --> E["执行受控攻击步骤"]
E --> F["浏览器回放验证"]
F --> G["收集日志与证据"]
G --> H["回写 Registry 与报告"]

运行时间线

时间步骤状态说明
2026-03-18T03:57:40+00:00select-advisorycompletednextjs--CVE-2025-49005
2026-03-18T03:57:40+00:00resolve-repro-profilecompletednextjs-proxy-boundary
2026-03-18T03:57:41+00:00doctorcompletedall checks passed
2026-03-18T03:57:43+00:00provision-compose-environmentready-
2026-03-18T03:57:43+00:00wait-readycompletedbaseline urls ready (1)
2026-03-18T03:57:43+00:00seed-environmentcompletedsteps=1
2026-03-18T03:57:43+00:00baseline-snapshotcompletedurls=1
2026-03-18T03:57:44+00:00browser-replay-before-attackcompleted-
2026-03-18T03:57:44+00:00controlled-attack-chaincompletedsteps=1
2026-03-18T03:57:45+00:00browser-replay-after-attackcompleted-
2026-03-18T03:57:45+00:00collect-logs-and-evidencecompletedcontainer_logs=1
2026-03-18T03:57:47+00:00cleanup-compose-environmentcompleteddocker compose down completed
2026-03-18T03:57:47+00:00update-registry-and-reportscompletednextjs-nextjs--CVE-2025-49005-20260318035740

攻击步骤

工具状态输出
nextjs.proxy-boundarycompleted/Users/x/websafe/06-case-studies/generated-runs/nextjs-nextjs--CVE-2025-49005-20260318035740/logs/attack.json

浏览器截图

证据清单