Vulnerabilities/

auth-js Vulnerable to Insecure Path Routing from Malformed User Input

Severity:
Low

Description

The library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs. This could lead to a URL path traversal, resulting in the wrong API function being called.

Recommendation

Update the @supabase/auth-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@supabase/auth-js
Anything's wrong? Let us know Last updated on May 05, 2026