Next.js是Vercel开源的一个 React 框架。 Next.js 14.2.25之前版本和15.2.3之前版本存在安全漏洞,该漏洞源于如果授权检查发生在中间件中,可能绕过授权检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Verify Next.js CVE-2025-29927 on Netlify not vulnerable | https://github.com/serhalp/test-cve-2025-29927 | POC Details |
| 2 | Next.js Middleware Authorization Bypass | https://github.com/Ademking/CVE-2025-29927 | POC Details |
| 3 | A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability | https://github.com/6mile/nextjs-CVE-2025-29927 | POC Details |
| 4 | undefined | https://github.com/azu/nextjs-cve-2025-29927-poc | POC Details |
| 5 | None | https://github.com/lirantal/vulnerable-nextjs-14-CVE-2025-29927 | POC Details |
| 6 | CVE-2025-29927 Proof of Concept | https://github.com/aydinnyunus/CVE-2025-29927 | POC Details |
| 7 | None | https://github.com/ticofookfook/poc-nextjs-CVE-2025-29927 | POC Details |
| 8 | Next.js における認可バイパスの脆弱性を再現するデモです。 | https://github.com/t3tra-dev/cve-2025-29927-demo | POC Details |
| 9 | Proof-of-Concept for Authorization Bypass in Next.js Middleware | https://github.com/websecnl/CVE-2025-29927-PoC-Exploit | POC Details |
| 10 | Authorization Bypass in Next.js Middleware | https://github.com/MuhammadWaseem29/CVE-2025-29927-POC | POC Details |
| 11 | CVE-2025-29927 lab | https://github.com/strobes-security/nextjs-vulnerable-app | POC Details |
| 12 | CVE-2025-29927 Exploit Checker | https://github.com/RoyCampos/CVE-2025-29927 | POC Details |
| 13 | Demo for Next.js middleware bypass - CVE-2025-29927 | https://github.com/fourcube/nextjs-middleware-bypass-demo | POC Details |
| 14 | Next.Js 权限绕过漏洞(CVE-2025-29927) | https://github.com/iSee857/CVE-2025-29927 | POC Details |
| 15 | CVE-2025-29927 Proof of Concept | https://github.com/Eve-SatOrU/POC-CVE-2025-29927 | POC Details |
| 16 | CVE-2025-29927 Authorization Bypass in Next.js Middleware | https://github.com/arvion-agent/next-CVE-2025-29927 | POC Details |
| 17 | Next.js Middleware Auth Bypass | https://github.com/Oyst3r1ng/CVE-2025-29927 | POC Details |
| 18 | New nuclei CVE | https://github.com/lediusa/CVE-2025-29927 | POC Details |
| 19 | None | https://github.com/lem0n817/CVE-2025-29927 | POC Details |
| 20 | CVE-2025-29927の検証 | https://github.com/kuzushiki/CVE-2025-29927-test | POC Details |
| 21 | A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass | https://github.com/ricsirigu/CVE-2025-29927 | POC Details |
| 22 | Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save results. Features connection pooling, caching, and chunked processing for fast performance | https://github.com/0xWhoknows/CVE-2025-29927 | POC Details |
| 23 | Nuclei Template: CVE-2025-29927 - Next.js Middleware Authentication Bypass | https://github.com/tobiasGuta/CVE-2025-29927-POC | POC Details |
| 24 | Sigma Rule for CVE-2025–29927 Detection | https://github.com/elshaheedy/CVE-2025-29927-Sigma-Rule | POC Details |
| 25 | Critical vulnerability in next.js : Bypass middleware authentication | https://github.com/furmak331/CVE-2025-29927 | POC Details |
| 26 | Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927) | https://github.com/takumade/ghost-route | POC Details |
| 27 | None | https://github.com/memmedrehimzade/CVE-2025-29927-vuln-app | POC Details |
| 28 | None | https://github.com/0xPb1/Next.js-CVE-2025-29927 | POC Details |
| 29 | None | https://github.com/jeymo092/cve-2025-29927 | POC Details |
| 30 | PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing. | https://github.com/alihussainzada/CVE-2025-29927-PoC | POC Details |
No public POC found.
Login to generate AI POCNo comments yet