Intel

AIKIDO-2025-10204

@opennextjs/aws is vulnerable to Authorization Bypass

Authorization BypassCVE-2025-29927 Published Apr 3, 2025

91

Critical Risk

This Affects:

JS@opennextjs/aws
2.3.0 - 3.5.3
Fixed in 3.5.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an authorization bypass due to improper validation of internal requests. The middleware exempts internal requests from authorization checks but fails to verify their authenticity, allowing attackers to spoof internal requests and bypass access controls. By crafting a request with a forged internal flag, an attacker can gain unauthorized access to protected routes or critical system functionalities.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@opennextjs/aws is vulnerable to Authorization Bypass in versions 2.3.0 - 3.5.3.

How to fix this

Upgrade the @opennextjs/aws library to the patch version.