- PUBLISHED ON
- Blog Published on:
This writeup details exploiting a Next.js auth bypass (CVE-2025-29927) to access a restricted app, then leveraging an LFI vulnerability to extract credentials from internal files. After gaining SSH access, a Terraform misconfiguration with sudo privileges is abused to escalate to root and capture both user and root flags.