PT-2025-47613 · Clerk · Clerk-Js

Published

2025-11-20

·

Updated

2025-11-25

·

CVE-2025-63700

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Clerk-js version 5.88.0
Description An issue allows attackers to bypass the OAuth authentication flow by manipulating the request during the OTP verification stage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-63700

Affected Products

Clerk-Js