Target Industry

Indiscriminate, opportunistic targeting.

Overview

Security researchers have discovered a severe vulnerability within Next.js, identified as CVE-2025-29927 (CVSS:3.1 : 9.1), that takes advantage of the middleware when authorisation checks are performed on it. This severe flaw will cause websites using middleware to become susceptible to manipulation and data theft. 

Impact

Exploitation of CVE-2025-29927 will lead to compromise of the admin panel. This will allow webpages to be edited as well as sensitive information being breached. Its realistically possible that this can lead to further exploitation. This is highly likely to lead to a loss of trust with customers as well as malicious changes to the website leading to exploitation of customers and potentially employees. 

Exploitation

This has yet to have a reallife case but a proof of concept (PoC) of how this has been performed has been released on zhero_web_security’s website. This exploit requires no preconditions making it simple to perform and imperative that Next.js is updated to the latest patch.  

Vulnerability Detection

All version prior 14.2.25 are vulnerable.  

All version prior 15.2.3 are vulnerable. 

Containment, Mitigations & Remediation

A patch is available for this vulnerability. Next.js users should update to version 14.2.25+ and 15.2.3 respectively for version 14 and 15. Ensure no changes have been made to the admin page after patching in case exploitation is already occurring. 

Threat Landscape

Developed by Vercel, Next.js is an open source React framework designed to build fast, scalable web applications with ease. By offering server-side rendering and static site generation. Next.js is widely used by developers and companies worldwide, including major brands like Apple, Nike, Netflix, TikTok, Uber, Starbucks, and Spotify. More than 17,000 companies are utilising Next.js for their web applications. Many of these businesses solely rely on their web presence for income and operations, making it an ideal attack surface for malicious actors. 

Threat Group

No attribution to recent specific threat actors or groups has beenidentifiedat the time of writing. 

Tactics, Techniques and Procedures

  • T1190 – Exploit Public-Facing Application: 
  • T1071.001 – Application Layer Protocol: Web Protocols: 
  • T1059 – Command and Scripting Interpreter: 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content