VDB
Sign up
HIGH8.8

GHSA-wpq7-q8j4-72jg

Auth0-js bypasses CSRF checks

Quick fix

GHSA-wpq7-q8j4-72jg — auth0-js: upgrade to the fixed version with the command below.

npm install auth0-js@9.3.0

Details

The Auth0.js library has a vulnerability affecting versions below 9.3 that allows an attacker to bypass the CSRF check from the state parameter if it's missing from the authorization response, leaving the client vulnerable to CSRF attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/auth0-js
Introduced in: 0Fixed in: 9.3.0
Fixnpm install auth0-js@9.3.0

References