MEDIUM
GHSA-pjr6-jx7r-j4r6
Auth0 NextJS SDK v4 Missing Session Invalidation
Quick fix
GHSA-pjr6-jx7r-j4r6 — @auth0/nextjs-auth0: upgrade to the fixed version with the command below.
npm install @auth0/nextjs-auth0@4.5.1Details
### Overview Auth0 NextJS `v4.0.1` to `v4.5.0` does not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid.
### Am I Affected? You are affected if you are using Auth0 NextJS SDK v4.
### Fix Upgrade to `v4.5.1`.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-pjr6-jx7r-j4r6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-46344[ADVISORY]
- https://github.com/auth0/nextjs-auth0/commit/a4f061aed02ffa132feca8adfbd11704df17e1c3[WEB]
- https://github.com/auth0/nextjs-auth0[PACKAGE]
- https://github.com/auth0/nextjs-auth0/releases/tag/v4.5.1[WEB]