Proof
Runtime proof
The controlled CVE-2025-29927 before/after run: 200 versus 307.
proof/run-proof.mjs installs real Next.js releases into two bundled demo apps, builds and starts them locally, and requests the protected /admin page with and without the bypass header.
header
x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware| Demo app | next | Normal request | With bypass header |
|---|---|---|---|
| Acme Dental (affected) | 14.2.24 | 307 redirect to login | 200 admin page served |
| Brightline Legal (fixed) | 14.2.25 | 307 redirect to login | 307 redirect to login |
Recorded in proof/proof-result.json at 2026-09-27T21:05:05Z with pass: true.
What this proves and what it does not
It proves that the conditions Pich checks for CVE-2025-29927 matter: the same app is exposed on 14.2.24 and not on 14.2.25. It does not prove anything about a real client’s production deployment, and it was not run against any public repository.