VDB
Sign up
HIGH8.0

GHSA-954c-jjx6-cxv7

Reflected XSS from the callback handler's error query parameter

Quick fix

GHSA-954c-jjx6-cxv7 — @auth0/nextjs-auth0: upgrade to the fixed version with the command below.

npm install @auth0/nextjs-auth0@1.4.2

Details

### Overview

Versions before and including `1.4.1` are vulnerable to reflected XSS. An attacker can execute arbitrary code by providing an XSS payload in the `error` query parameter which is then processed by the callback handler as an error message.

### Am I affected? You are affected by this vulnerability if you are using `@auth0/nextjs-auth0` version `1.4.1` or lower **unless** you are using custom error handling that does not return the error message in an HTML response.

### How to fix that? Upgrade to version `1.4.2`.

### Will this update impact my users? The fix adds basic HTML escaping to the error message and it should not impact your users.

### Credit

https://github.com/inian https://github.com/git-ishanpatel

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@auth0/nextjs-auth0
Introduced in: 0Fixed in: 1.4.2
Fixnpm install @auth0/nextjs-auth0@1.4.2

References