Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Automated-Next.js-Security-Scanner-for-CVE-2025-29927 — This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist. | Kitploit
工具/GitHubGitHub/ferpalma21/automated-next.js-security-scanner-for-cve-2025-29927
ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersExploitationInformation GatheringWeb Security
GitHubferpalma21/automated-next.js-security-scanner-for-cve-2025-29927

Automated-Next.js-Security-Scanner-for-CVE-2025-29927

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.

查看仓库
2203天前尚未审核
内容在请求的语言中不可用。显示英文版本。

Next.js CVE-2025-29927 Vulnerability Scanner

A command-line security scanner for identifying publicly accessible Next.js applications that may be exposed to CVE-2025-29927.

Disclaimer

This tool is intended for authorized security testing, vulnerability assessment, research, and defensive security work.

Only scan systems that you own or have explicit permission to test.

The scanner performs external fingerprinting and, when explicitly requested, active security testing. A result reported as potentially vulnerable should not be treated as definitive proof of compromise.

Features

  • Identifies websites using Next.js.
  • Checks Next.js version to determine vulnerability.
  • Attempts to exploit vulnerable sites (trial).
  • Supports custom Chromium path for Puppeteer.
  • Allows URL input from a file or command-line arguments.
  • Follows redirects (optional, may cause false positives).
  • Outputs results to a JSON object or a file.

Installation

Through Github

# Clone the repository
git clone https://github.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927.git
cd Automated-Next.js-Security-Scanner-for-CVE-2025-29927.git

# Install dependencies
npm install

Install globally:

npm install -g nextjs-cve-2025-29927-scanner

## Usage
Run the script with different options:
```sh
node index.js -u "https://example.com" -v

Command-line Arguments

OptionAliasDescription
-u--urlsList of URLs (space/comma-separated)
-f--fileFile containing URLs (one per line)
-c--chromePath to Chromium (default: /snap/bin/chromium)
-o--outputFile to save vulnerable site results
-v--verboseEnables detailed output
-r--redirectFollows redirects (optional, may lead to false positives)
-a--attackAttempts exploitation (use with caution)
-w--wordlistWordlist file for exploitation
-t--headlessRuns Puppeteer in headless mode
-x--headersIf fails to exploit will retry with different headers

Example Usages

Scan a single website

node index.js -u "https://example.com"

Scan multiple websites

node index.js -u "https://site1.com, https://site2.com"

Scan websites from a file

node index.js -f urls.txt

Save results to a file

node index.js -u "https://example.com" -o results.txt

Run in verbose mode

node index.js -u "https://example.com" -v

Attempt exploitation (use with caution!)

node index.js -u "https://example.com" -a -w wordlist.txt

Output

  • Verbose Mode (-v): Detailed logs printed to the console.
  • JSON Output: When -v is not set, results are printed as JSON.
  • File Output (-o): Saves detected vulnerabilities to a file.

Example Output (Verbose Mode)

Analyzing: https://example.com
https://example.com is running Next.js version: 13.5.9.
Potentially vulnerable to CVE-2025-29927.

Notes

  • Use at your own risk. Ensure you have permission to scan websites.
  • Set the correct Chromium path if Puppeteer fails to launch.

Remediation

Upgrade to Next.js 14.2.25 or 15.2.3 or later. If upgrading is not possible, block the x-middleware-subrequest header at the WAF or server level. Patched versions: 15.2.3, 14.2.25, 13.5.9, 12.3.5

Next Steps

  • Error handling and retry logic
  • Get emails from website and send an automatic email to the owners of the website

License

This project is licensed under the MIT License.

下载工具