VDB
Sign up
HIGH8.8

GHSA-wv26-rj8c-4r33

Cross-Site Request Forgery (CSRF) in Auth0

Quick fix

GHSA-wv26-rj8c-4r33 — auth0-js: upgrade to the fixed version with the command below.

npm install auth0-js@9.0.0

Details

CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/auth0-js
Introduced in: 0Fixed in: 9.0.0
Fixnpm install auth0-js@9.0.0

References