@clerk/tanstack-react-start is vulnerable to Cross-site Scripting (XSS)
71
High Risk
Affected versions of this package are vulnerable to stored cross-site scripting (XSS). Clerk auth state is serialized with JSON.stringify into SSR <script> tags, so a </script> sequence in user-controllable session claims can break out of the script element and execute attacker-controlled JavaScript. The patch escapes <, >, and / (via htmlSafeJson) while preserving identical JSON.parse values on the client.
You are affected if you are using a version that falls within the vulnerable range.
@clerk/tanstack-react-start is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 1.4.19.
Upgrade the @clerk/tanstack-react-start library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant