Auth0.js
by Auth0
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-6873 | Cri | 0.64 | 9.8 | 0.02 | Apr 4, 2018 | The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated. | ||
| CVE-2017-17068 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2017 | A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback… | ||
| CVE-2026-42280 | Hig | 0.46 | 7.1 | 0.00 | May 27, 2026 | Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is… | ||
| CVE-2020-5263 | 0.00 | — | 0.01 | Apr 9, 2020 | auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the… |
- risk 0.64cvss 9.8epss 0.02
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
- risk 0.49cvss 7.5epss 0.01
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback…
- risk 0.46cvss 7.1epss 0.00
Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is…
- CVE-2020-5263Apr 9, 2020risk 0.00cvss —epss 0.01
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the…