🎄 Join our Annual Holiday wargame and win prizes!


CVE-2025-29927: Next.JS Authorization Bypass Secure Coding Challenge

26/03/2025

:warning: In light of the newly identified Next.js authorization bypass (CVE-2025-29927), we’re making our “Middleware.js” secure coding challenge completely free to access :gift:.

This vulnerability exemplifies how business logic flaws can slip through standard security scans—modern vulnerabilities don’t always follow patterns that scanners can easily detect. Let’s learn from this real-world scenario and prevent similar oversights in our own code.

Try the challenge here: https://play.secdim.com/game/javascript/challenge/middlewarejs

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more