Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2025-29927-lab — Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice. | Kitploit
Tools/GitHubGitHub/metasploit403/cve-2025-29927-lab
Authentication & AuthorizationVulnerability AnalysisWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubmetasploit403/cve-2025-29927-lab

cve-2025-29927-lab

Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
116 months agoNot yet reviewed

This repository contains a deliberately vulnerable web application built using Next.js. It is designed to demonstrate and study the security issue known as CVE-2025-29927. The goal of this project is to help security researchers, students, and bug bounty hunters understand how the vulnerability works in a real-world-like environment.

[!CAUTION ] This application is intentionally insecure and should never be deployed in production.

🔩Purpose

  • Learn how the vulnerability works
  • Practice identifying and exploiting it safely
  • Understand the impact of insecure middleware handling
  • Improve bug bounty and web security skills

🐞Vulnerability

CVE-2025-29927 is related to improper handling of request logic in applications built with Next.js, particularly in middleware.This can allow attackers to:

  1. Bypass authentication or authorization checks
  2. Manipulate request flow using crafted headers or inputs
  3. Access restricted resources

📁Project Structure

  • app/ → Application routes
  • middleware.ts → Contains vulnerable logic
  • api/ → Backend endpoints (including protected routes)

⚙️Installation & Setup

git clone https://github.com/metasploit403/cve-2025-29927-lab
cd cve-2025-29927-lab
npm install
npm run dev

🪲Vulnerable Endpoints

Some routes are intentionally vulnerable and may include

- /api/admin/secret
- /api/internal/health
- /api/private/data

These endpoints simulate restricted resources that should not be accessible without proper authorization.

🔥Exploitation

1.Assumed you have clone the repo successfully
2.Start npm run dev
3.This run your project locally
4.Open browser of your choice i.e chrome and type http://localhost:3000
5.Try accessing any of the 3 API endpoint

- /api/admin/secret
- /api/internal/health
- /api/private/data

6.Now try it with any endpoint

- http://localhost:3000/api/admin/secret
- http://localhost:3000/api/internal/health
- http://localhost:3000/api/private/data

7.Observe that your request is blocked,this is because you have not included cookie in your request.This mean that the endpoint point is guarded by the middleware.middleware is checking if you request have a cookie and if doesn't it is automatically being blocked

8.Now let add cookie to our request.To do this open the chrome devtool (I'm using chrome browser here,you can use any browser you like)

9.press F12 and chrome devtool will open

10.Go to console tab

11.in the console tab type document.cookie="lab-auth=authenticated"

12.Now refresh the page and observe that you are login

Keep in mind that middleware is checking if request contain cookie.if request has cookie you login successfully and if not you are blocked. The question is HOW can we bypass middleware check and login without providing cookie.This is what CVE-2025-29927 allow as to do

Now let bypass the middleware auth check with CVE-2025-29927.The trick here is just to add This specific header
x-middleware-subrequest: middleware. This header is suppose to be used internally only by Framework.if we add it the middleware will stop checking if our request have cookie And now any sensitive endpoint in you application is defenseless

To Exploit This Let use cURL.
curl is a command-line tool used to send requests to server and get response back

1.Expect 401 without cookie

curl.exe -i http://localhost:3000/api/admin/secret

observe the server responded with status code 307 temporary redirect.Because there is no cookie we are redirected to the homepage/The root page.This means we cannot login unless we provide cookie.

2.curl.exe -i http://localhost:3000/api/admin/secret -H "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware"

Now we added "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware"
Observe that we now have access the login without the cookie.This is complete auth bypass

🔐Mitigation

To fix issues like this in real applications:

  • Never trust client-controlled headers blindly
  • Validate all inputs in middleware
  • Implement proper authentication checks server-side
  • Avoid relying on insecure request assumptions
  • Upgrade to the patched version of next
  • If in some case you cannot upgrade strip x-middleware-subrequest header at reverse proxies

🫵Who is this for?

  • Bug bounty hunters
  • Security researchers
  • Students learning web security
  • Developers who want to understand secure middleware design

⛔Disclaimer

This project is for educational purposes only. Do not use these techniques on systems you do not own or have explicit permission to test.

🤝Contributing

Feel free to:

  • Improve the lab
  • Add new vulnerable scenarios
  • Submit fixes or better explanations

⭐Support

If you find this useful, consider starring the repository.

🏷️Tags

- Next.js 
- Bug Bounty 
- Web Security 
- CVE-2025-29927 
- Middleware Authentication 
- Bypass
Download Tool