Description
An issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 5.88.0
References
Could your website be exposed too?
SmartScanner can check your website for Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/react-router - CVE-2025-53548
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nuxt - CVE-2025-53548
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nextjs - CVE-2025-53548
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/backend - CVE-2025-53548
You might also like:
See something that needs correcting? Let us knowUpdated November 21, 2025


