PT-2026-38263 · Auth0 · Auth0.Js
Aleister1102
+1
·
Published
2026-05-06
·
Updated
2026-06-04
·
CVE-2026-42280
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
auth0-js versions 8.11.0 through 9.32.0
Description
Improper validation in the Auth0.js SDK may allow the return of user profile data when a specifically crafted invalid ID token is used in conjunction with a valid access token. This issue occurs in applications where access control relies on rules defined in Auth0 Actions, potentially leading to unauthorized information disclosure.
Recommendations
Update auth0-js to version 10.0.0 or greater.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Auth0.Js