NextSniper
exploitNext.js exploitation scanner — CVE-2025-29927 & CVE-2025-55182 middleware bypass + RSC traversal modules. Confirmed RCE on production AWS EC2.
I'm Yunus Emre Öztaş (@ynsmroztas / mitsec) — a security researcher and bug bounty hunter. I hunt critical bugs across web, mobile and API surfaces, and I ship the zero-dependency tooling I use to find them.
Arsenal
Next.js exploitation scanner — CVE-2025-29927 & CVE-2025-55182 middleware bypass + RSC traversal modules. Confirmed RCE on production AWS EC2.
Rootless Android pentest suite via Frida Gadget injection on Termux. 8-layer SSL pinning bypass, secret scanner, schema-aware deeplink fuzzer, autopilot.
Next.js / Vercel bundle intelligence — chunk harvesting, source-map recovery, endpoint & secret extraction with an HTML report per target.
POST endpoint discovery + HTML form parsing with body-parameter injection across SQLi / XSS / SSTI / RCE / LFI / CRLF / Open Redirect.
CVE-2026-21643 scanner for FortiClientEMS — PostgreSQL injection via Site header, CAST-trick error extraction, time-based blind fallback.
Shodan REST asset mapper — multi-query harvest, DNS domain API, IP↔port↔domain↔cert correlation and httpx target generation.
Writeups
A low-severity user enumeration primitive escalated into an unauthenticated database dump through a chained IDOR and a leaky export endpoint.
Turning a harmless HTML injection into account takeover by clobbering a script-loader config object and pivoting through a permissive postMessage handler.
Gadget injection workflow on Termux: repacking, 8-layer pinning bypass, and automated secret extraction on non-rooted devices.
Disclosure
Next.js RSC — React Server Components deserialization leading to remote code execution.
Next.js — Middleware authorization bypass via crafted internal subrequest header.
Metabase — Pre-authentication remote code execution through the setup token endpoint.
Laravel / Ignition — Debug-mode file write chained to RCE via log poisoning.
Capability
Contact