Intel

AIKIDO-2025-10192

@auth0/nextjs-auth0 is vulnerable to Access Token Exposure

Access Token Exposure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 31, 2025

65

Medium Risk

This Affects:

JS@auth0/nextjs-auth0
4.0.2 - 4.2.1
Fixed in 4.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by a design flaw where access tokens could be inadvertently exposed to browser-based applications due to a misconfiguration of the access control in the auth endpoint, violating OAuth best practices. An attacker could take leverage of this flaw to steal tokens via client-side attacks, potentially leading to an account takeover.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@auth0/nextjs-auth0 is vulnerable to Access Token Exposure in versions 4.0.2 - 4.2.1.

How to fix this

Upgrade the @auth0/nextjs-auth0 library to the patch version.