Target Industry
Indiscriminate, opportunistic targeting.
Overview
Security researchers have discovered a severe vulnerability within Next.js, identified as CVE-2025-29927 (CVSS:3.1 : 9.1), that takes advantage of the middleware when authorisation checks are performed on it. This severe flaw will cause websites using middleware to become susceptible to manipulation and data theft.
Impact
Exploitation of CVE-2025-29927 will lead to compromise of the admin panel. This will allow webpages to be edited as well as sensitive information being breached. It’s realistically possible that this can lead to further exploitation. This is highly likely to lead to a loss of trust with customers as well as malicious changes to the website leading to exploitation of customers and potentially employees.
Exploitation
This has yet to have a real–life case but a proof of concept (PoC) of how this has been performed has been released on zhero_web_security’s website. This exploit requires no preconditions making it simple to perform and imperative that Next.js is updated to the latest patch.
Vulnerability Detection
All version prior 14.2.25 are vulnerable.
All version prior 15.2.3 are vulnerable.
Containment, Mitigations & Remediation
A patch is available for this vulnerability. Next.js users should update to version 14.2.25+ and 15.2.3 respectively for version 14 and 15. Ensure no changes have been made to the admin page after patching in case exploitation is already occurring.
Threat Landscape
Developed by Vercel, Next.js is an open source React framework designed to build fast, scalable web applications with ease. By offering server-side rendering and static site generation. Next.js is widely used by developers and companies worldwide, including major brands like Apple, Nike, Netflix, TikTok, Uber, Starbucks, and Spotify. More than 17,000 companies are utilising Next.js for their web applications. Many of these businesses solely rely on their web presence for income and operations, making it an ideal attack surface for malicious actors.
Threat Group
No attribution to recent specific threat actors or groups has been identified at the time of writing.
Tactics, Techniques and Procedures
- T1190 – Exploit Public-Facing Application:
- T1071.001 – Application Layer Protocol: Web Protocols:
- T1059 – Command and Scripting Interpreter:
Further Information













