RANGE
Vulnerability monitoring · Isolated application testing

Vulnerabilities mapped to the software deployed in each environment.

Range combines repository, SBOM, container, and runtime inventories. It identifies affected components, reports whether they are deployed to Production, and supports isolated application security tests.

Vulnerability analysis Production impact
CriticalPublished 21 Mar 2025

CVE-2025-29927

Next.js authorization bypass in middleware

Executive summary

The deployed customer-portal uses Next.js 15.2.2 middleware for authorization and serves a public Production endpoint.

Affected component
customer-portal
Container image · 9f31c2
next@15.2.2
↳ Source · commit 9f31c2a
Affected environment
Production
AWS · ap-southeast-2
11 workloads4 public endpoints
Suggested version
next@15.2.3
Analysis complete
[01] Inventory and deployment context

Connect software inventories and deployment data.

Versioned component inventories are grouped into environments using runtime and infrastructure data. CVE matches can then be evaluated against what is deployed.

01

Components

Create versioned software inventories from repositories, container images, hosts, and SBOMs.

02

Environments

Group the component versions currently deployed to Production, Staging, or another environment.

03

Vulnerabilities

Review the affected package, components, environments, advisory, and available fixed version.

[02] Vulnerability review

Review findings with Production context.

Northstar / VulnerabilityProduction
CVE-2025-29927customer-portalCRITICAL
CVE-2024-45337no production impactHIGH
CVE-2023-34104feature branch onlyHIGH
[03] Application security testing

Run tests against an isolated application environment.

Configure the application, environment recipe, permitted test classes, and execution limits. Follow the active investigation and review the resulting security report.

View pen tests →
RUN-1048 · Running62%
10:04:12
Indexed authorization middleware
10:04:25
Hypothesis: invoice route may omit tenant scope
10:04:31
Testing synthetic tenant boundary
Inspect application trace
Environment
range-job-1048
Egress
Blocked
[04] Pricing

Plans for monitoring and testing.

Basic
$499
per month

Vulnerability monitoring and deployment context.

  • → Continuous CVE monitoring
  • → Component and Environment inventories
  • → Production impact summaries
  • → Email, Slack, and PagerDuty alerts
Join waitlist
Pro
From $1,499
per month

Monitoring plus AI application security testing.

  • → Everything in Basic
  • → 10 AI pen tests / month
  • → Isolated test environments
  • → Security reports and recommended remediation
Join waitlist
[05] Private beta

Request access to the private beta.