HIGH8.8
GHSA-wv26-rj8c-4r33
Cross-Site Request Forgery (CSRF) in Auth0
Quick fix
GHSA-wv26-rj8c-4r33 — auth0-js: upgrade to the fixed version with the command below.
npm install auth0-js@9.0.0Details
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
Are you affected?
Enter the version of the package you're using.