A critical Next.js flaw tracked as CVE-2025-29927 exposed applications using middleware-based authorization to authentication and authorization bypass, allowing protected routes to be reached without intended access checks. Public reporting described the issue as a middleware bypass bug affecting deployments that relied on Next.js middleware for security decisions, prompting urgent guidance for defenders to identify exposed internet-facing applications and remediate vulnerable implementations.
The vulnerability was rapidly operationalized after disclosure, with multiple GitHub repositories publishing proof-of-concept exploits, vulnerable demo apps, Docker labs, and automated detection tools. These included scanners and hunters designed to identify susceptible Next.js sites, as well as exploitation-focused projects advertising middleware auth bypass and route access validation, increasing the likelihood of broad reconnaissance and opportunistic abuse against unpatched environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository described a Next.js authentication bypass proof of concept tied to CVE-2025-29927 and referenced an Edge Runtime environment leak via the middleware bug. This added a new technical angle to public research around the vulnerability.
A further GitHub repository dedicated to CVE-2025-29927 appeared, indicating ongoing public discussion and reposting of material related to the vulnerability.
Another GitHub repository released a vulnerable application demo for the Next.js middleware bypass, extending the set of public training and reproduction resources.
A GitHub repository published an educational Next.js authentication bypass demo for CVE-2025-29927, showing continued interest in reproducing the flaw months after initial disclosure.
A Docker-based lab environment for CVE-2025-29927 was published on GitHub, providing a packaged setup for reproducing and studying the Next.js middleware bypass.
Throughout April 2025, multiple additional GitHub repositories appeared covering CVE-2025-29927, including exploit material, educational write-ups, and automated scanners that could optionally attempt exploitation. This reflects sustained community attention and growing accessibility of offensive and defensive tooling.
Additional repositories released a vulnerability detector ('ghost-route') and another demo environment for reproducing the Next.js middleware bypass. Public tooling around the flaw continued to mature after initial disclosure.
GitHub repositories began publishing scanner tools to test whether websites were vulnerable to CVE-2025-29927. This expanded the issue from proof-of-concept exploitation to broader internet-scale detection activity.
Another GitHub repository dedicated to CVE-2025-29927 was published, indicating continued public sharing of exploit or reproduction material for the Next.js vulnerability.
More GitHub demo repositories for the Next.js middleware bypass appeared, and public security reporting described CVE-2025-29927 as a critical middleware authentication bypass issue affecting Next.js deployments. The reporting focused on what defenders should know and how to respond.
A public proof-of-concept repository for CVE-2025-29927, describing an authorization bypass in Next.js middleware, was published on GitHub. This marks early public weaponization and technical disclosure of the issue.
17 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcesocradar.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.