I ran your exploit-rce-v4.js with and without the patched react-server-dom-webpack, and both of them executed the RCE.
So I don't think this mechanism is exactly correct, can you demo it with an actual nextjs project, instead of your mock server?
So I don't think this mechanism is exactly correct, can you demo it with an actual nextjs project, instead of your mock server?
1. npm start 2. npm run exploit
I'm debugging it currently, maybe I'm not on the right path after all.