webPromedium
Lab 113 — CloudNest
hackadvisor
Task: Next.js cloud management platform with middleware-based route protection for /admin. Solution: CVE-2025-29927 bypass using x-middleware-subrequest header with 5+ colon-separated values to skip authentication middleware.
$ ls tags/ techniques/
nextjs_middleware_recursion_bypassauthentication_bypass_via_framework_vulnerabilityhoneypot_flag_identification
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 248 — PulseBoard — Next.js Middleware Authorization Bypass— hackadvisor
- [web][Pro]Lab 372 — PipelineIQ — Next.js Middleware Authorization Bypass— hackadvisor
- [web][Pro]Lanternfall— neurogrid
- [web][Pro]Lab 328 — DataNest — NoSQL Operator Injection in Authentication— hackadvisor
- [web][free]ReactOOPS— hackthebox