Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
- Severity:
- Medium
Description
An issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 5.88.0
References
- GHSA-3mm3-wfpv-q85g
- clerk.com
- CVE-2025-63700
- CWE-290
- CWE-639
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
- OWASP 2021-A7
Related Issues
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/react-router - CVE-2025-53548
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nuxt - CVE-2025-53548
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nextjs - CVE-2025-53548
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/backend - CVE-2025-53548
You might also like:
- Tags:
- npm
- @clerk/clerk-js
Anything's wrong? Let us know Last updated on November 21, 2025


