Pich logoPichdocs
Docs menu: Runtime proof

Proof

Runtime proof

The controlled CVE-2025-29927 before/after run: 200 versus 307.

proof/run-proof.mjs installs real Next.js releases into two bundled demo apps, builds and starts them locally, and requests the protected /admin page with and without the bypass header.

header
x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware
Demo appnextNormal requestWith bypass header
Acme Dental (affected)14.2.24307 redirect to login200 admin page served
Brightline Legal (fixed)14.2.25307 redirect to login307 redirect to login

Recorded in proof/proof-result.json at 2026-09-27T21:05:05Z with pass: true.

What this proves and what it does not

It proves that the conditions Pich checks for CVE-2025-29927 matter: the same app is exposed on 14.2.24 and not on 14.2.25. It does not prove anything about a real client’s production deployment, and it was not run against any public repository.

Edit this page on GitHub