
This is a CVE-2025-29927 Scanner.
This is a professional-grade scanner designed to detect the CVE-2025-29927 middleware bypass vulnerability in Next.js applications.
X-Middleware-Subrequest headers to bypass Next.js middlewarepip install -r requirements.txt
playwright install
python main.py --domain https://example.com --threads 10 --timeout 10 --save
python main.py --help
| Option | Description |
|---|---|
--domain | Target site base URL (required) |
--user-agent | Custom user-agent (default: Chrome string) |
--timeout | Request timeout (default: 10 seconds) |
--proxy | Proxy address (optional) |
--save | Save results to results.txt |
--threads | Number of threads (default: 10) |
--wordlist | Worlist include Common Path |
docker build -t cve-scanner .
docker run -it --rm cve-scanner --domain https://example.com --save
This project includes a GitHub Actions workflow to test setup on push. It:
--help checkSee .github/workflows/python.yml.
.
├── main.py # Entry point
├── config.py # CLI parser
├── crawler.py # Playwright crawler
├── scanner.py # Multi-threaded vulnerability testing
├── requirements.txt
├── Dockerfile
└── .github/workflows
Overview of CVE-2025-29927 Vulnerability
CVE-2025-29927 is a critical Next.js security flaw that allows attackers to bypass middleware-based authentication and authorization. By including a special internal header (X-Middleware-Subrequest) in HTTP requests, an attacker can trick the Next.js server into skipping middleware execution, thereby gaining access to protected routes. In practice, a request that would normally be blocked by authentication middleware (e.g. returning a 401/403 or redirecting to login) is processed normally if this header is present, effectively bypassing security checks. This vulnerability affects Next.js versions 11.1.4 through 15.2.2, and administrators are urged to patch or implement mitigations (such as stripping this header at proxies) to protect their applications.
Detecting this vulnerability in a web application requires discovering internal endpoints and testing them with the malicious header to see if unauthorized access is possible. Below is a design plan for an advanced Python script that will crawl a target website (with full JavaScript support) and scan for CVE-2025-29927, meeting all the specified requirements.
To fulfill the requirement of deep crawling including JavaScript-rendered content, we will use Playwright (preferred over Selenium for its speed and modern API). Playwright is a powerful headless browser automation library that can handle dynamic web apps and modern JS frameworks. Compared to Selenium, Playwright offers a more modern API (built on Chrome DevTools Protocol) and supports both synchronous and asynchronous operation, which can yield better performance for our use case . Key libraries and their installation instructions include:
playwright – for headless browser automation (to load SPAs or pages requiring JS). (Install: pip install playwright and run playwright install to get browser binaries).
requests or httpx – for sending HTTP requests during the scanning phase. We can use requests for simplicity or httpx/aiohttp for async support. (Install: pip install requests or pip install httpx).
bs4 (BeautifulSoup) – for parsing HTML and extracting links when needed. Playwright can directly query the DOM, but using BeautifulSoup on the page’s HTML content is straightforward for finding anchor tags. (Install: pip install beautifulsoup4).
concurrent.futures (built-in) or asyncio – to implement concurrency. For multi-threading, Python’s concurrent.futures.ThreadPoolExecutor will be used (no extra install). If using an async approach, Python’s asyncio with httpx can be used for parallel requests.
(Optional) argparse – for parsing command-line arguments if we want a CLI interface instead of an interactive menu. (built-in module)
(Optional) rich or colorama – for colored or formatted console output to enhance readability. (Install: pip install rich or pip install colorama).
Justification: Playwright is chosen for its ability to scrape dynamic content without heavy complexities. “Using Playwright we can automate headless browsers... to navigate the web just like a human, which makes it great for scraping dynamic JavaScript-powered websites”. This ensures our crawler can see links or UI elements that are generated by scripts (which a simple requests-based crawler would miss).
The crawler module will use Playwright in headless mode to perform deep crawling of the target site. The goal is to discover internal paths (endpoints) to test, including those only revealed after JS execution. Key design points for the crawler:
Headless Browser Navigation: Launch a browser instance (e.g. Chromium) in headless mode via Playwright. Use a Browser Context with a custom User-Agent if specified by the user (more on that in the next section). For example, we can create a context with browser.new_context(user_agent=<user_agent_string>) to emulate the chosen User-Agent. If a proxy is configured, apply it at launch (Playwright allows setting a proxy server when launching the browser or context).
Recursive Crawling Strategy: Start from a given base URL (seed). Use page.goto(base_url, timeout=<T>) to load the page (timeout configurable). Wait for network to be idle or a short delay to allow dynamic content to load if necessary. Then extract links. We can extract links by either:
links = page.evaluate("Array.from(document.querySelectorAll('a[href]'), a => a.href)"), or<a href> attributes.