@auth0/nextjs-auth0 is vulnerable to Access Token Exposure
65
Medium Risk
Affected versions of this package are affected by a design flaw where access tokens could be inadvertently exposed to browser-based applications due to a misconfiguration of the access control in the auth endpoint, violating OAuth best practices. An attacker could take leverage of this flaw to steal tokens via client-side attacks, potentially leading to an account takeover.
You are affected if you are using a version that falls within the vulnerable range.
@auth0/nextjs-auth0 is vulnerable to Access Token Exposure in versions 4.0.2 - 4.2.1.
Upgrade the @auth0/nextjs-auth0 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant