WRITEUP · PLATFORM · NEXT.JS · @YNSMROZTAS

NextForge — class matrix, not a kit

● liveclk --:--:--v2.1 · --full

One file. Point it at an authorized Next.js lab. It fingerprints App Router / Pages / middleware / Turbopack, lights only the matching class, and prints curl plus a report snippet. Shell stays off unless you ask.

next // forgeobserve
radar--:--:--
Next.jsRSC FlightSSRFmiddlewareauthorized lab

Summary

Next.js stopped being one surface years ago. App Router, Pages Router, middleware, Turbopack, Server Actions, RSC Flight, incremental cache each have their own parser and their own year of CVEs. A generic scan-the-host script either misses the class or fills the report with 404 noise.

NextForge is the operator pass for that stack. Profile first. Matrix second. Evidence third. The public helper lives on GitHub. This page is the class note: what it looks for, what it refuses to call a hit, and what a redacted lab session prints.

No payload bodies on this page. No live cloud host. No IMDS secrets. The still below is a classifier tape from an authorized lab labeled lab.nextforge.local.

Redacted NextForge session
Lab still. Real hostname, digest bytes and cloud metadata painted out. --full only. Shell never opened.

What the tool is

A single Python file. No daemon. No SaaS. You give it a URL you already have written scope for.

python3 nextforge.py -t https://lab.nextforge.local --full
profile → matching class → curl snippet → report block
--auto   operator mode. shell only after a closed hit.
--pipe   subfinder | httpx | nextforge. shell never opens.

--full is the report pass. Matching techniques run. It does not drop a shell. --auto is the operator pass: if a class closes, the session can hand you a prompt. --pipe is detect-only on purpose.

CVE-2026-64649 (Server Action host-header SSRF) needs an out-of-band listener. If --oast is missing the tool marks the class ready and does not fire. Blind SSRF noise is how reports die.

Fingerprint before fire

The first packets are not exploits. They are a profile:

If the version string is not public, NextForge does not invent one. Classes that need a confirmed parser only light when the marker is there.

NextForge class matrix
Four buckets. Fingerprint decides which lights. The rest stay dark.

The matrix (class, not recipe)

Names below are public CVE classes. This page does not reprint request bodies, gadget chains or Flight payloads.

The 75604 rule

Windows cache traversal is the noisiest class. Encoded ..\ plus a 404 is not a hit. NextForge only closes 75604 when all of this is true:

404 + %5c..%5c     ignored
200 + encryptionKey  class closed
do not file 75604 on a path list

Redacted lab pass

Authorized lab. Host renamed. Cloud metadata and digest bytes stripped. Mode was --full.

NextForge v2.1  target https://lab.nextforge.local
fingerprint     App Router · RSC Flight · x-nextjs-*
middleware      header present
turbopack       absent

class 55182 / 66478  Flight RCE
confirm             digest resolved uid=1001
HIT                 RCE class closed · host [REDACTED]

class 75604         Win cache
paths               404 + encoded traversal  ignored
confirm rule        200 + marker only

class 44578         WS-upgrade SSRF · no OAST this pass
class 64649         Host SSRF · ready, not fired (--oast off)

mode                --full · report only · shell never opened
mitsec@nextforge:

The RCE class closed because the Flight digest carried a process marker, not because the status line was 500. That distinction matters when a WAF returns 500 on every odd Content-Type.

WAF and parser notes

Managed edges rewrite Flight and multipart in ways that look like a miss. NextForge tags a blocked probe edge-ate instead of safe. Safe means the class was reached and the parser rejected it. Edge-ate means you never spoke to the app.

Cloud IMDS probes exist in the operator binary for authorized cloud labs. This page does not print those URLs or any harvested keys.

What this page will not do

If you need the operator file, it is the public repo. If you need a finding, attach the curl snippet NextForge already prints and the confirm rule from this note.

Fix posture (defenders)

Repo

NextForge stays on GitHub. Classifier model only. Written scope. Own lab.

Open github.com/ynsmroztas/NextForge →

YUNUS EMRE ÖZTAŞ · MITSEC · AUTHORIZED TESTING ONLY