Description
Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is fixed in 10.0.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8qjv-jj2q-x832 | Auth.js SDK has Improper Permission Checking |
References
History
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is fixed in 10.0.0. | |
| Title | Improper Permission Checking in Auth.js SDK | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T14:39:15.789Z
Reserved: 2026-04-26T11:53:27.717Z
Link: CVE-2026-42280
No data.
Status : Received
Published: 2026-05-27T15:16:27.753
Modified: 2026-05-27T15:16:27.753
Link: CVE-2026-42280
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA