Next.js是Vercel开源的一个 React 框架。 Next.js 14.2.25之前版本和15.2.3之前版本存在安全漏洞,该漏洞源于如果授权检查发生在中间件中,可能绕过授权检查。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Verify Next.js CVE-2025-29927 on Netlify not vulnerable | https://github.com/serhalp/test-cve-2025-29927 | POC详情 |
| 2 | Next.js Middleware Authorization Bypass | https://github.com/Ademking/CVE-2025-29927 | POC详情 |
| 3 | A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability | https://github.com/6mile/nextjs-CVE-2025-29927 | POC详情 |
| 4 | undefined | https://github.com/azu/nextjs-cve-2025-29927-poc | POC详情 |
| 5 | None | https://github.com/lirantal/vulnerable-nextjs-14-CVE-2025-29927 | POC详情 |
| 6 | CVE-2025-29927 Proof of Concept | https://github.com/aydinnyunus/CVE-2025-29927 | POC详情 |
| 7 | None | https://github.com/ticofookfook/poc-nextjs-CVE-2025-29927 | POC详情 |
| 8 | Next.js における認可バイパスの脆弱性を再現するデモです。 | https://github.com/t3tra-dev/cve-2025-29927-demo | POC详情 |
| 9 | Proof-of-Concept for Authorization Bypass in Next.js Middleware | https://github.com/websecnl/CVE-2025-29927-PoC-Exploit | POC详情 |
| 10 | Authorization Bypass in Next.js Middleware | https://github.com/MuhammadWaseem29/CVE-2025-29927-POC | POC详情 |
| 11 | CVE-2025-29927 lab | https://github.com/strobes-security/nextjs-vulnerable-app | POC详情 |
| 12 | CVE-2025-29927 Exploit Checker | https://github.com/RoyCampos/CVE-2025-29927 | POC详情 |
| 13 | Demo for Next.js middleware bypass - CVE-2025-29927 | https://github.com/fourcube/nextjs-middleware-bypass-demo | POC详情 |
| 14 | Next.Js 权限绕过漏洞(CVE-2025-29927) | https://github.com/iSee857/CVE-2025-29927 | POC详情 |
| 15 | CVE-2025-29927 Proof of Concept | https://github.com/Eve-SatOrU/POC-CVE-2025-29927 | POC详情 |
| 16 | CVE-2025-29927 Authorization Bypass in Next.js Middleware | https://github.com/arvion-agent/next-CVE-2025-29927 | POC详情 |
| 17 | Next.js Middleware Auth Bypass | https://github.com/Oyst3r1ng/CVE-2025-29927 | POC详情 |
| 18 | New nuclei CVE | https://github.com/lediusa/CVE-2025-29927 | POC详情 |
| 19 | None | https://github.com/lem0n817/CVE-2025-29927 | POC详情 |
| 20 | CVE-2025-29927の検証 | https://github.com/kuzushiki/CVE-2025-29927-test | POC详情 |
| 21 | A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass | https://github.com/ricsirigu/CVE-2025-29927 | POC详情 |
| 22 | Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save results. Features connection pooling, caching, and chunked processing for fast performance | https://github.com/0xWhoknows/CVE-2025-29927 | POC详情 |
| 23 | Nuclei Template: CVE-2025-29927 - Next.js Middleware Authentication Bypass | https://github.com/tobiasGuta/CVE-2025-29927-POC | POC详情 |
| 24 | Sigma Rule for CVE-2025–29927 Detection | https://github.com/elshaheedy/CVE-2025-29927-Sigma-Rule | POC详情 |
| 25 | Critical vulnerability in next.js : Bypass middleware authentication | https://github.com/furmak331/CVE-2025-29927 | POC详情 |
| 26 | Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927) | https://github.com/takumade/ghost-route | POC详情 |
| 27 | None | https://github.com/memmedrehimzade/CVE-2025-29927-vuln-app | POC详情 |
| 28 | None | https://github.com/0xPb1/Next.js-CVE-2025-29927 | POC详情 |
| 29 | None | https://github.com/jeymo092/cve-2025-29927 | POC详情 |
| 30 | PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing. | https://github.com/alihussainzada/CVE-2025-29927-PoC | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论