Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Automated-Next.js-Security-Scanner-for-CVE-2025-29927 — This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist. | Kitploit
Tools/GitHubGitHub/ferpalma21/automated-next.js-security-scanner-for-cve-2025-29927
ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersExploitationInformation GatheringWeb Security
GitHubferpalma21/automated-next.js-security-scanner-for-cve-2025-29927

Automated-Next.js-Security-Scanner-for-CVE-2025-29927

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.

View Repository
2203 days agoNot yet reviewed

Next.js CVE-2025-29927 Vulnerability Scanner

A command-line security scanner for identifying publicly accessible Next.js applications that may be exposed to CVE-2025-29927.

Disclaimer

This tool is intended for authorized security testing, vulnerability assessment, research, and defensive security work.

Only scan systems that you own or have explicit permission to test.

The scanner performs external fingerprinting and, when explicitly requested, active security testing. A result reported as potentially vulnerable should not be treated as definitive proof of compromise.

Features

  • Identifies websites using Next.js.
  • Checks Next.js version to determine vulnerability.
  • Attempts to exploit vulnerable sites (trial).
  • Supports custom Chromium path for Puppeteer.
  • Allows URL input from a file or command-line arguments.
  • Follows redirects (optional, may cause false positives).
  • Outputs results to a JSON object or a file.

Installation

Through Github

# Clone the repository
git clone https://github.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927.git
cd Automated-Next.js-Security-Scanner-for-CVE-2025-29927.git

# Install dependencies
npm install

Install globally:

npm install -g nextjs-cve-2025-29927-scanner

## Usage
Run the script with different options:
```sh
node index.js -u "https://example.com" -v

Command-line Arguments

OptionAliasDescription
-u--urlsList of URLs (space/comma-separated)
-f--fileFile containing URLs (one per line)
-c--chromePath to Chromium (default: /snap/bin/chromium)
-o--outputFile to save vulnerable site results
-v--verboseEnables detailed output
-r--redirectFollows redirects (optional, may lead to false positives)
-a--attackAttempts exploitation (use with caution)
-w--wordlistWordlist file for exploitation
-t--headlessRuns Puppeteer in headless mode
-x--headersIf fails to exploit will retry with different headers

Example Usages

Scan a single website

node index.js -u "https://example.com"

Scan multiple websites

node index.js -u "https://site1.com, https://site2.com"

Scan websites from a file

node index.js -f urls.txt

Save results to a file

node index.js -u "https://example.com" -o results.txt

Run in verbose mode

node index.js -u "https://example.com" -v

Attempt exploitation (use with caution!)

node index.js -u "https://example.com" -a -w wordlist.txt

Output

  • Verbose Mode (-v): Detailed logs printed to the console.
  • JSON Output: When -v is not set, results are printed as JSON.
  • File Output (-o): Saves detected vulnerabilities to a file.

Example Output (Verbose Mode)

Analyzing: https://example.com
https://example.com is running Next.js version: 13.5.9.
Potentially vulnerable to CVE-2025-29927.

Notes

  • Use at your own risk. Ensure you have permission to scan websites.
  • Set the correct Chromium path if Puppeteer fails to launch.

Remediation

Upgrade to Next.js 14.2.25 or 15.2.3 or later. If upgrading is not possible, block the x-middleware-subrequest header at the WAF or server level. Patched versions: 15.2.3, 14.2.25, 13.5.9, 12.3.5

Next Steps

  • Error handling and retry logic
  • Get emails from website and send an automatic email to the owners of the website

License

This project is licensed under the MIT License.

Download Tool