VDB
Sign up
MEDIUM6.4

GHSA-2mqv-4j3r-vjvp

Open redirect in @auth0/nextjs-auth0

Quick fix

GHSA-2mqv-4j3r-vjvp — @auth0/nextjs-auth0: upgrade to the fixed version with the command below.

npm install @auth0/nextjs-auth0@1.6.2

Details

### Overview

Versions `<=1.6.1` do not filter out certain `returnTo` parameter values from the login url, which expose the application to an open redirect vulnerability.

### Am I affected? You are affected by this vulnerability if you are using `@auth0/nextjs-auth0` version `<=1.6.1`.

### How to fix that? Upgrade to version `>=1.6.2`

### Will this update impact my users? The fix provided in the patch will not affect your users.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@auth0/nextjs-auth0
Introduced in: 0Fixed in: 1.6.2
Fixnpm install @auth0/nextjs-auth0@1.6.2

References