🚀 Submit a Challenge — SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

CVE-2025-29927: Next.JS Authorization Bypass Secure Coding Challenge

News1 min read

:warning: In light of the newly identified Next.js authorization bypass (CVE-2025-29927), we’re making our “Middleware.js” secure coding challenge completely free to access :gift:.

This vulnerability exemplifies how business logic flaws can slip through standard security scans—modern vulnerabilities don’t always follow patterns that scanners can easily detect. Let’s learn from this real-world scenario and prevent similar oversights in our own code.

Try the challenge here: https://play.secdim.com/game/javascript/challenge/middlewarejs

Questions or comments? Discuss this post on SecDim Community →

Try it yourself

Find, Hack and Fix Your First Vulnerability

Reading about security bugs is one thing — fixing one is how the skill sticks. Play a free challenge from the wargame, no setup required.