Vulnerabilities/

Auth.js SDK has Improper Permission Checking

Severity:
High

Description

Under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided.

Recommendation

Update the auth0-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
auth0-js
Anything's wrong? Let us know Last updated on May 06, 2026