$ cat writeup.md…
$ cat writeup.md…
bug-makers
Task: Next.js application with middleware-based authentication protecting /forbidden route, outdated framework version. Solution: CVE-2025-29927 — bypass middleware auth by sending x-middleware-subrequest header with 5 colon-separated entries to skip middleware execution.
Permission denied (requires tier.pro)
Sign in with GitHub or Discord to continue. No email required.
$sign in$ grep --similar