Impact
The Auth0 react-native-auth0 SDK's web platform implementation does not isolate its in‑memory token cache to individual user sessions when running in a server‑side rendering environment where module state persists across HTTP requests. This flaw means that access tokens stored in memory for one user can be retrieved by subsequent requests handled by the same server runtime, exposing sensitive credentials and permitting unauthorized access to protected resources. The vulnerability is classified as CWE‑488, reflecting improper separation of token data across sessions.
Affected Systems
Auth0 react-native-auth0 library versions earlier than 5.11.1 that use web platform credential management in a server‑side rendering configuration where module state is shared between requests are affected. Systems deploying these earlier versions in such an environment are at risk of token leakage.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not provided, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that an attacker would need to target a server running the vulnerable SDK in an environment that shares module state across requests. If such conditions exist, an attacker could read tokens from memory and gain unauthorized access, making the risk moderate to high in heavily trafficked applications.
OpenCVE Enrichment