webPromedium

Lab 113 — CloudNest

hackadvisor

Task: Next.js cloud management platform with middleware-based route protection for /admin. Solution: CVE-2025-29927 bypass using x-middleware-subrequest header with 5+ colon-separated values to skip authentication middleware.

$ ls tags/ techniques/
nextjs_middleware_recursion_bypassauthentication_bypass_via_framework_vulnerabilityhoneypot_flag_identification

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups