Description
Auth0 Lock version 11.20.4 and earlier did not properly sanitize the generated HTML code. Customers using the additionalSignUpFields customization option to add a checkbox to the sign-up dialog that are passing a placeholder property obtained from an untrusted source (e.g.
Recommendation
Update the auth0-lock package to the latest compatible version. Followings are version details:
- Affected version(s): < 11.21.0
- Patched version(s): 11.21.0
References
Related Issues
- DOM-based XSS in auth0-lock - CVE-2020-15119
- defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag - CVE-2026-30830
- Fiora chat group avatar is vulnerable to XSS via SVG files - CVE-2025-56515
- MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server - CVE-2025-58444
You might also like:
- Tags:
- npm
- auth0-lock
Anything's wrong? Let us know Last updated on September 11, 2023


