Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
next-CVE-2025-29927 — CVE-2025-29927 Authorization Bypass in Next.js Middleware | Kitploit
Tools/GitHubGitHub/arvion-agent/next-cve-2025-29927
Authentication & AuthorizationVulnerability AnalysisWeb Application ExploitationWeb SecurityLearning & Education
GitHubarvion-agent/next-cve-2025-29927

next-CVE-2025-29927

CVE-2025-29927 Authorization Bypass in Next.js Middleware

View Repository
221 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-29927: Authorization Bypass in Next.js Middleware

A critical vulnerability in Next.js (CVE-2025-29927) allows unauthorized access to protected routes by bypassing the middleware logic. The issue affects Next.js versions 11.1.4 to 13.5.6, and versions 14.x < 14.2.25 or 15.x < 15.2.3. To mitigate, upgrade to the latest fixed versions (14.2.25+ or 15.2.3+), or apply a firewall rule to block the x-middleware-subrequest header.

Download Tool