Vulnerability library
Security checkMay 05, 2026

auth-js Vulnerable to Insecure Path Routing from Malformed User Input

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs. This could lead to a URL path traversal, resulting in the wrong API function being called.

Recommendation

Update the @supabase/auth-js package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 2.69.1
  • Patched version(s): 2.70.0

References

Could your website be exposed too?

SmartScanner can check your website for auth-js Vulnerable to Insecure Path Routing from Malformed User Input and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated May 05, 2026