Description
Versions before and including 11.30.0 are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library’s
flashMessagefeature is utilized and user input or data from URL parameters is incorporated into theflashMessage.
Recommendation
Update the auth0-lock package to the latest compatible version. Followings are version details:
- Affected version(s): < 11.30.1
- Patched version(s): 11.30.1
References
Related Issues
- Svelte vulnerable to XSS when using objects during server-side rendering - CVE-2022-25875
- Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - CVE-2025-26619
- Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - vega - CVE-2025-26619
- Plate media plugins has a XSS in media embed element when using custom URL parsers - CVE-2024-40631
You might also like:
- Tags:
- npm
- auth0-lock
Anything's wrong? Let us know Last updated on February 01, 2023


