Skip to content
KitploitKITPLOIT
HerramientasBlog
Log in
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Automated-Next.js-Security-Scanner-for-CVE-2025-29927 — This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist. | Kitploit
Herramientas/GitHubGitHub/ferpalma21/automated-next.js-security-scanner-for-cve-2025-29927
ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersExploitationInformation GatheringWeb Security
GitHubferpalma21/automated-next.js-security-scanner-for-cve-2025-29927

Automated-Next.js-Security-Scanner-for-CVE-2025-29927

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →

This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.

Ver Repositorio
221hace 3 díasAún no revisado
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

Next.js CVE-2025-29927 Vulnerability Scanner

A command-line security scanner for identifying publicly accessible Next.js applications that may be exposed to CVE-2025-29927.

Disclaimer

This tool is intended for authorized security testing, vulnerability assessment, research, and defensive security work.

Only scan systems that you own or have explicit permission to test.

The scanner performs external fingerprinting and, when explicitly requested, active security testing. A result reported as potentially vulnerable should not be treated as definitive proof of compromise.

Features

  • Identifies websites using Next.js.
  • Checks Next.js version to determine vulnerability.
  • Attempts to exploit vulnerable sites (trial).
  • Supports custom Chromium path for Puppeteer.
  • Allows URL input from a file or command-line arguments.
  • Follows redirects (optional, may cause false positives).
  • Outputs results to a JSON object or a file.

Installation

Through Github

# Clone the repository
git clone https://github.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927.git
cd Automated-Next.js-Security-Scanner-for-CVE-2025-29927.git

# Install dependencies
npm install

Install globally:

npm install -g nextjs-cve-2025-29927-scanner

## Usage
Run the script with different options:
```sh
node index.js -u "https://example.com" -v

Command-line Arguments

OptionAliasDescription
-u--urlsList of URLs (space/comma-separated)
-f--fileFile containing URLs (one per line)
-c--chromePath to Chromium (default: /snap/bin/chromium)
-o--outputFile to save vulnerable site results
-v--verboseEnables detailed output
-r--redirectFollows redirects (optional, may lead to false positives)
-a--attackAttempts exploitation (use with caution)
-w--wordlistWordlist file for exploitation
-t--headlessRuns Puppeteer in headless mode
-x--headersIf fails to exploit will retry with different headers

Example Usages

Scan a single website

node index.js -u "https://example.com"

Scan multiple websites

node index.js -u "https://site1.com, https://site2.com"

Scan websites from a file

node index.js -f urls.txt

Save results to a file

node index.js -u "https://example.com" -o results.txt

Run in verbose mode

node index.js -u "https://example.com" -v

Attempt exploitation (use with caution!)

node index.js -u "https://example.com" -a -w wordlist.txt

Output

  • Verbose Mode (-v): Detailed logs printed to the console.
  • JSON Output: When -v is not set, results are printed as JSON.
  • File Output (-o): Saves detected vulnerabilities to a file.

Example Output (Verbose Mode)

Analyzing: https://example.com
https://example.com is running Next.js version: 13.5.9.
Potentially vulnerable to CVE-2025-29927.

Notes

  • Use at your own risk. Ensure you have permission to scan websites.
  • Set the correct Chromium path if Puppeteer fails to launch.

Remediation

Upgrade to Next.js 14.2.25 or 15.2.3 or later. If upgrading is not possible, block the x-middleware-subrequest header at the WAF or server level. Patched versions: 15.2.3, 14.2.25, 13.5.9, 12.3.5

Next Steps

  • Error handling and retry logic
  • Get emails from website and send an automatic email to the owners of the website

License

This project is licensed under the MIT License.

Descargar herramienta