Vulnerabilities/

Reflected XSS from the callback handler's error query parameter

Severity:
High

Description

Versions before and including 1.4.1 are vulnerable to reflected XSS. An attacker can execute arbitrary code by providing an XSS payload in the error query parameter which is then processed by the callback handler as an error message.

Recommendation

Update the @auth0/nextjs-auth0 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@auth0/nextjs-auth0
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing