Skip to content

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts. Details: Read Here

This uses Next.js version 15.2.2. The vulnerability allows the user to bypass the middleware script which contains the verification and can access the admin page without login. This can be done by adding the Header x-middleware-subrequest: src/middleware:src/middleware:src/middleware:src/middleware:src/middleware to the request

This could be used as CTF challenge.

About

A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Used by

Contributors

Languages