
Comprehensive demonstration of CVE-2025-32421 Eclipse technique - a sophisticated race condition attack against Next.js 15.0.4 that bypasses the original CVE-2024-46982 patch.
Comprehensive demonstration of CVE-2025-32421 Eclipse technique - a sophisticated race condition attack against Next.js 15.0.4 that bypasses the original CVE-2024-46982 patch.
This laboratory is designed exclusively for:
DO NOT USE FOR:
The Eclipse technique exploits a race condition in Next.js 15.0.4's promise batcher mechanism, allowing attackers to share cached results between requests and leak sensitive server-side data that should remain private.
/_error-0 cacheKey collisionCVE-2025-32421/
├── exploits/
│ ├── cve-2025-32421-eclipse-exploit.js
│ ├── cve-2025-32421-demo.js
│ ├── cve-2025-32421-simple-demo.js
│ └── cve-2025-32421-xss-eclipse.js
├── pages/
│ ├── _app.tsx
│ ├── _app_xss_cve2025.tsx
│ ├── _error.tsx
│ ├── index.tsx
│ └── 404.tsx
├── package.json
├── next.config.js
├── README.md
└── tsconfig.json
npm install
npm start
node exploits/cve-2025-32421-demo.js
node exploits/cve-2025-32421-eclipse-exploit.js
node exploits/cve-2025-32421-xss-eclipse.js --demo
node exploits/cve-2025-32421-xss-eclipse.js
Promise Batcher Exploitation: 100% success
Data Exposure Rate: 50/50 attempts
Monitoring Config Leaked: YES
Admin Preferences Exposed: YES
Race Condition Reliability: Perfect
XSS Injection Success: 6/6 payloads
Eclipse Data Exposure: 100%
Combined Attack Rate: 100%
Critical Vulnerability: CONFIRMED
/_error-0 cacheKey manipulationtheme parameterrole=admin cookie for elevated privilegesgetInitialPropsThis research is based on the Eclipse technique documentation by zhero-web-sec. The implementation demonstrates both the original Eclipse attack and an enhanced XSS combination variant.
This code is provided for educational and research purposes only. Users are responsible for ensuring compliance with all applicable laws and obtaining proper authorization before testing. The authors assume no liability for misuse of this software.
Status: Complete Implementation (100% Success Rate)
Last Updated: October 10, 2025
Vulnerability: CVE-2025-32421 + XSS Combined
Framework: Next.js 15.0.4