VDB
Sign up
HIGH7.5

GHSA-3mm3-wfpv-q85g

Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage

Details

An issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@clerk/clerk-js
Introduced in: 0

No fixed version published yet for @clerk/clerk-js (npm). Pin to a known-safe version or switch to an alternative.

References