Auth0 Next.js SDK
97%
Total Score
83
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-67716 @auth0/nextjs-auth0 is vulnerable to Incomplete List of Disallowed Inputs in versions 4.9.0 - 4.13.0. | 4.9.0 - 4.13.0 | Low |
CVE-2025-67490 @auth0/nextjs-auth0 is vulnerable to Incorrect Authorization in versions 4.11.0 - 4.11.2 and 4.12.0 - 4.12.1. | 4.11.0 - 4.11.24.12.0 - 4.12.1 | Medium |
CVE-2025-48947 @auth0/nextjs-auth0 is vulnerable to Use of Web Browser Cache Containing Sensitive Information in versions 4.0.1 - 4.6.0. | 4.0.1 - 4.6.0 | High |
AIKIDO-2025-10276 @auth0/nextjs-auth0 is vulnerable to Insufficient Session Expiration in versions 4.0.2 - 4.5.0. | 4.0.2 - 4.5.0 | Medium |
AIKIDO-2025-10192 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @auth0/nextjs-auth0 is vulnerable to Access Token Exposure in versions 4.0.2 - 4.2.1. | 4.0.2 - 4.2.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
swr Version ^2.2.5 | — | — |
jose Version ^6.0.11 | — | — |
@panva/hkdf Version ^1.2.1 | — | — |
oauth4webapi Version ^3.8.2 | — | — |
openid-client Version ^6.8.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant