Description
Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router.
Recommendation
Update the @clerk/nextjs package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.7.0, < 4.29.3
- Patched version(s): 4.29.3
References
Could your website be exposed too?
SmartScanner can check your website for @clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing - CVE-2026-1664
- Official Clerk JavaScript SDKs: Middleware-based route protection bypass - @clerk/nextjs - CVE-2026-41248
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nextjs - CVE-2025-53548
- Insecure Direct Object Reference (IDOR) - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated January 15, 2024


