Description
Under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided.
Recommendation
Update the auth0-js package to the latest compatible version. Followings are version details:
- Affected version(s): >= 8.11.0, <= 9.32.0
- Patched version(s): 10.0.0
References
Related Issues
- @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue - CVE-2026-8769
- payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments) - CVE-2026-25574
- LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set( - CVE-2026-40190
- @better-auth/sso: SSO provider may allow registration for any org member without a checking their role - CVE-2026-53515
You might also like:
- Tags:
- npm
- auth0-js
Anything's wrong? Let us know Last updated on June 08, 2026


