{"repo":"AnonKryptiQuz/NextSploit","free":true,"listed":false,"github":"https://github.com/AnonKryptiQuz/NextSploit","clone":"git clone https://github.com/AnonKryptiQuz/NextSploit.git","description":"NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js","language":"Python","stars":92,"topics":["anonymous","authentication-bypass","automation","cve-2025-29927","ethical-hacking","hacking","nextjs","penetration-testing","python","security-testing"],"license":null,"category":"security-tools","readme_excerpt":"🔍 NextSploit: Next.js CVE-2025-29927 Scanner & Exploiter ⚠️ NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927 , a security flaw in Next.js. The tool first identifies if a target website is running Next.js and determines whether its version falls within the vulnerable range. If the website is confirmed to be vulnerable, the tool automatically attempts to exploit the issue by bypassing middleware protections, potentially granting unauthorized access to restricted pages. --- 🚀 Features - 🔍 Automated Next.js Version Detection : Uses Wappalyzer to check if the target website runs Next.js and retrieves its version. - 🛡️ Vulnerability Assessment : Determines if the detected version is within the known vulnerable range. - ⚔️ Middleware Exploitation Test : Attempts to exploit the CVE-2025-29927 vulnerability using middleware headers. - 🌐 Automated Chrome Browser Launch : Opens the target URL with necessary headers preconfigured to bypass authentication (if vulnerable). - 📡 Mass URL Scanning : Allows scanning of multiple URLs simultaneously. --- Requirements 🛠️ - 🐍 Python 3.7+ - 🧪 Selenium - 🚗 ChromeDriver - 🦊 GeckoDriver - 🕵️ Wappalyzer CLI - 🌐 Google Chrome --- Installation 📥 1. Clone the repository: 2. Install required Python packages: 3. Download ChromeDriver Ensure ChromeDriver is installed and accessible: 🔗 ChromeDriver Download 4. GeckoDriver 🦊 Ensure GeckoDriver is installed and accessible --- Usage 💻 1. ✅️ Run the tool: 2. ✅️ Foll","default_branch":null,"files":null,"tree":[],"storefront":"/r/AnonKryptiQuz","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/AnonKryptiQuz/NextSploit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}