Description
Auth0 Lock version 11.20.4 and earlier did not properly sanitize the generated HTML code. Customers using the additionalSignUpFields customization option to add a checkbox to the sign-up dialog that are passing a placeholder property obtained from an untrusted source (e.g.
Recommendation
Update the auth0-lock package to the latest compatible version. Followings are version details:
- Affected version(s): < 11.21.0
- Patched version(s): 11.21.0
References
Related Issues
- Vercel ms Inefficient Regular Expression Complexity vulnerability - CVE-2017-20162
- Axios is vulnerable to DoS attack through lack of data size check - CVE-2025-58754
- billboard.js allows prototype pollution via the function generate - CVE-2025-49223
- Parse Server's custom object ID allows to acquire role privileges - CVE-2024-47183
- Tags:
- npm
- auth0-lock
Anything's wrong? Let us know Last updated on September 11, 2023