@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)
- Severity:
- High
Description
Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router.
Recommendation
Update the @clerk/nextjs package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.7.0, < 4.29.3
- Patched version(s): 4.29.3
References
- GHSA-q6w5-jg5q-47vg
- clerk.com
- CVE-2024-22206
- CWE-284
- CWE-287
- CWE-639
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
- OWASP 2021-A7
Related Issues
- Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing - CVE-2026-1664
- Official Clerk JavaScript SDKs: Middleware-based route protection bypass - @clerk/nextjs - CVE-2026-41248
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nextjs - CVE-2025-53548
- Insecure Direct Object Reference (IDOR) - Vulnerability
You might also like:
- Tags:
- npm
- @clerk/nextjs
Anything's wrong? Let us know Last updated on January 15, 2024


