Vulnerabilities/

Auth0 NextJS SDK v4 Missing Session Invalidation

Severity:
Medium

Description

Auth0 NextJS v4.0.1 to v4.5.0 does not invoke .setExpirationTime when generating a JWE token for the session. As a result, the JWE does not contain an internal expiration claim. While the session cookie may expire or be cleared, the JWE remains valid.

Recommendation

Update the @auth0/nextjs-auth0 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@auth0/nextjs-auth0
Anything's wrong? Let us know Last updated on April 30, 2025

This issue is available in SmartScanner Professional

See Pricing