npm package
auth0-js
pkg:npm/auth0-js
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-42280 | Hig | 7.1 | >= 8.11.0, < 10.0.0 | 10.0.0 | May 27, 2026 | Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is | |
| CVE-2020-5263 | — | >= 8.0.0, < 9.13.2 | 9.13.2 | Apr 9, 2020 | auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the use | ||
| CVE-2018-6874 | Hig | 8.8 | < 9.0.0 | 9.0.0 | Apr 4, 2018 | CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled. | |
| CVE-2018-7307 | Hig | 8.8 | < 9.3.0 | 9.3.0 | Mar 6, 2018 | The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter. | |
| CVE-2017-17068 | Hig | 7.5 | < 8.12.0 | 8.12.0 | Dec 6, 2017 | A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback pa |
- affected >= 8.11.0, < 10.0.0fixed 10.0.0
Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is
- CVE-2020-5263Apr 9, 2020affected >= 8.0.0, < 9.13.2fixed 9.13.2
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the use
- affected < 9.0.0fixed 9.0.0
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
- affected < 9.3.0fixed 9.3.0
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
- affected < 8.12.0fixed 8.12.0
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback pa