Vulnerabilities/

Official Clerk JavaScript SDKs: Middleware-based route protection bypass

Severity:
High

Description

createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers.

Sessions are not compromised and no existing user can be impersonated - the bypass only affects the middleware-level gating decision.

Recommendation

Update the @clerk/nuxt package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@clerk/nuxt
Anything's wrong? Let us know Last updated on April 27, 2026