HIGH7.5npm
GHSA-3mm3-wfpv-q85g· CVE-2025-63700Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
Modified: 11/21/2025
package
pkg:npm/%40clerk/clerk-js
Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
Modified: 11/21/2025
Clerk has an authorization bypass when combining organization, billing, or reverification checks
Modified: 9/10/2026