Vulnerabilities/

Open redirect in @auth0/nextjs-auth0

Severity:
Medium

Description

Versions <=1.6.1 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect vulnerability.

Recommendation

Update the @auth0/nextjs-auth0 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@auth0/nextjs-auth0
Anything's wrong? Let us know Last updated on February 01, 2023