Description
Auth0 Lock version 11.20.4 and earlier did not properly sanitize the generated HTML code. Customers using the additionalSignUpFields customization option to add a checkbox to the sign-up dialog that are passing a placeholder property obtained from an untrusted source (e.g.
Recommendation
Update the auth0-lock package to the latest compatible version. Followings are version details:
- Affected version(s): < 11.21.0
- Patched version(s): 11.21.0
References
Related Issues
- DOM-based XSS in auth0-lock - CVE-2020-15119
- Astro vulnerable to reflected XSS via the server islands feature - CVE-2025-64764
- sanitize-html is vulnerable to XSS through incomprehensive sanitization - CVE-2019-25225
- jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin - CVE-2025-9910
- Tags:
- npm
- auth0-lock
Anything's wrong? Let us know Last updated on September 11, 2023