VYPR
High severity8.1NVD Advisory· Published Jun 4, 2021· Updated Jun 17, 2026

CVE-2021-32641

CVE-2021-32641

Description

auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including 11.30.0 are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's flashMessage feature is utilized and user input or data from URL parameters is incorporated into the flashMessage or the library's languageDictionary feature is utilized and user input or data from URL parameters is incorporated into the languageDictionary. The vulnerability is patched in version 11.30.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
auth0-locknpm
< 11.30.111.30.1

Affected products

3
  • Auth0/Lock2 versions
    cpe:2.3:a:auth0:lock:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:auth0:lock:*:*:*:*:*:*:*:*range: <11.30.1
    • (no CPE)range: <= 11.30.0
  • ghsa-coords
    Range: < 11.30.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.