webPromedium

Lab 372 — PipelineIQ — Next.js Middleware Authorization Bypass

hackadvisor

Task: PipelineIQ sales platform with Next.js middleware-based admin authorization. Solution: Bypass middleware using CVE-2025-29927 x-middleware-subrequest header to access admin secrets endpoint.

$ ls tags/ techniques/
header_injectionauthorization_bypassnextjs_middleware_subrequest_bypassmiddleware_recursion_exploit

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups