Exploitation Summary
EIP tracks 3 public exploits for CVE-2025-29972. PoCs published by ThemeHackers, TH-SecForge.
AI-analyzed exploit summary This PoC demonstrates an authorization bypass in Next.js by manipulating the `x-middleware-subrequest` header to skip middleware security checks. It tests for vulnerability by comparing responses with and without the header.
Description
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
Exploits (3)
This PoC demonstrates an authorization bypass in Next.js by manipulating the `x-middleware-subrequest` header to skip middleware security checks. It tests for vulnerability by comparing responses with and without the header.
This PoC demonstrates an authorization bypass in Next.js by manipulating the `x-middleware-subrequest` header to skip middleware security checks. It tests for vulnerability by comparing responses with and without the header.
The repository contains a functional Python exploit for CVE-2025-29972, which bypasses Next.js middleware authorization checks by manipulating the `x-middleware-subrequest` header. The exploit sends crafted HTTP requests to test for vulnerability and checks for protected content in responses.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H