webPromedium
Lab 372 — PipelineIQ — Next.js Middleware Authorization Bypass
hackadvisor
Task: PipelineIQ sales platform with Next.js middleware-based admin authorization. Solution: Bypass middleware using CVE-2025-29927 x-middleware-subrequest header to access admin secrets endpoint.
$ ls tags/ techniques/
header_injectionauthorization_bypassnextjs_middleware_subrequest_bypassmiddleware_recursion_exploit
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 248 — PulseBoard — Next.js Middleware Authorization Bypass— hackadvisor
- [web][Pro]Lab 327 — PipelineIQ — NoSQL Injection Authentication Bypass— hackadvisor
- [web][Pro]Lab 113 — CloudNest— hackadvisor
- [web][Pro]Lab 329 — PipelineIQ — NoSQL Injection Authentication Bypass— hackadvisor
- [web][Pro]Lab 373 — PipelineIQ — Django ORM Filter Injection— hackadvisor