Description
Under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided.
Recommendation
Update the auth0-js package to the latest compatible version. Followings are version details:
- Affected version(s): >= 8.11.0, <= 9.32.0
- Patched version(s): 10.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Auth.js SDK has Improper Permission Checking and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue - CVE-2026-8769
- payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments) - CVE-2026-25574
- LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set( - CVE-2026-40190
- @better-auth/sso: SSO provider may allow registration for any org member without a checking their role - CVE-2026-53515
You might also like:
See something that needs correcting? Let us knowUpdated June 08, 2026


