{"repo":"UNICORDev/exploit-CVE-2025-29927","free":true,"listed":false,"github":"https://github.com/UNICORDev/exploit-CVE-2025-29927","clone":"git clone https://github.com/UNICORDev/exploit-CVE-2025-29927.git","description":"Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass","language":"Python","stars":12,"topics":["authorization","bypass","exploit","middleware","nextjs","python","python3"],"license":null,"category":"auth-billing-email","readme_excerpt":"Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass Like this repo? Give us a ⭐! For educational and authorized security research purposes only. Exploit Author @UNICORDev by (@NicPWNs and @Dev-Yeoj) Vulnerability Description Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3. Exploit Description In vulnerable Next.js versions, it is possible to bypass authorization checks within an application, if the authorization check occurs in middleware, by sending requests which contain the x-middleware-subrequest header. This exploit assesses a target's Next.js version and sends various specially crafted headers to achieve middleware bypass. Usage Options Download Download exploit-CVE-2025-29927.py Here Exploit Requirements - python3 - python3:requests - python3:selenium Demo Tested On Next.js Version 13.5.6 Applies To - Next.js Versions 15.0.0 - 15.2.2 - Next.js Versions 14.0.0 - 14.2.24 - Next.js Versions 13.0.0 - 13.5.8 - Next.js Versions 11.1.4 - 12.3.4 Test Environment Credits - https://nvd.nis","default_branch":null,"files":null,"tree":[],"storefront":"/r/UNICORDev","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/UNICORDev/exploit-CVE-2025-29927/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}