
Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.
This repository contains a deliberately vulnerable web application built using Next.js. It is designed to demonstrate and study the security issue known as CVE-2025-29927. The goal of this project is to help security researchers, students, and bug bounty hunters understand how the vulnerability works in a real-world-like environment.
[!CAUTION ] This application is intentionally insecure and should never be deployed in production.
CVE-2025-29927 is related to improper handling of request logic in applications built with Next.js, particularly in middleware.This can allow attackers to:
git clone https://github.com/metasploit403/cve-2025-29927-lab
cd cve-2025-29927-lab
npm install
npm run dev
Some routes are intentionally vulnerable and may include
- /api/admin/secret
- /api/internal/health
- /api/private/data
These endpoints simulate restricted resources that should not be accessible without proper authorization.
1.Assumed you have clone the repo successfully
2.Start npm run dev
3.This run your project locally
4.Open browser of your choice i.e chrome and type http://localhost:3000
5.Try accessing any of the 3 API endpoint
- /api/admin/secret
- /api/internal/health
- /api/private/data
6.Now try it with any endpoint
- http://localhost:3000/api/admin/secret
- http://localhost:3000/api/internal/health
- http://localhost:3000/api/private/data
7.Observe that your request is blocked,this is because you have not included cookie in your request.This mean that the endpoint point is guarded by the middleware.middleware is checking if you request have a cookie and if doesn't it is automatically being blocked
8.Now let add cookie to our request.To do this open the chrome devtool (I'm using chrome browser here,you can use any browser you like)
9.press F12 and chrome devtool will open
10.Go to console tab
11.in the console tab type document.cookie="lab-auth=authenticated"
12.Now refresh the page and observe that you are login
Keep in mind that middleware is checking if request contain cookie.if request has cookie you login successfully and if not you are blocked. The question is HOW can we bypass middleware check and login without providing cookie.This is what CVE-2025-29927 allow as to do
Now let bypass the middleware auth check with CVE-2025-29927.The trick here is just to add This specific header
x-middleware-subrequest: middleware.
This header is suppose to be used internally only by Framework.if we add it the middleware will stop checking if our request have cookie And now any sensitive endpoint in you application is defenseless
To Exploit This Let use cURL.
curl is a command-line tool used to send requests to server and get response back
1.Expect 401 without cookie
curl.exe -i http://localhost:3000/api/admin/secret
observe the server responded with status code 307 temporary redirect.Because there is no cookie we are redirected to the homepage/The root page.This means we cannot login unless we provide cookie.
2.curl.exe -i http://localhost:3000/api/admin/secret -H "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware"
Now we added "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware"
Observe that we now have access the login without the cookie.This is complete auth bypass
To fix issues like this in real applications:
This project is for educational purposes only. Do not use these techniques on systems you do not own or have explicit permission to test.
Feel free to:
If you find this useful, consider starring the repository.
- Next.js
- Bug Bounty
- Web Security
- CVE-2025-29927
- Middleware Authentication
- Bypass