HIGH7.5npm
GHSA-9mp4-77wg-rwx9· CVE-2025-53548@clerk/backend Performs Insufficient Verification of Data Authenticity
Modified: 7/9/2025
package
pkg:npm/%40clerk/backend
@clerk/backend Performs Insufficient Verification of Data Authenticity
Modified: 7/9/2025
Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host
Modified: 4/6/2026
Clerk has an authorization bypass when combining organization, billing, or reverification checks
Modified: 9/10/2026