Clerk Backend SDK - REST Client for Backend API & JWT verification utilities
88%
Total Score
healthy
Active releases, broad maintenance, signed provenance, and strong packaging outweigh limited workflow hygiene concerns.
The repository name does not match the package and its README does not mention @clerk/backend, creating some uncertainty about package-to-repository linkage. The organization-owned monorepo context makes a name mismatch ordinary, but the absent README mention still warrants caution.
All 16 workflows were analyzed with no untrusted checkout or script-injection findings, and all 88 action references are pinned. High-confidence template-injection findings and several ad hoc package installs remain workflow hygiene concerns, though no dangerous trigger-and-sink combination was observed.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-125473 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @clerk/backend is vulnerable to Authentication Bypass in versions 2.33.0 - 3.11.6. | 2.33.0 - 3.11.6 | Medium |
CVE-2026-34076 @clerk/backend is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.0.0 - 3.2.2. | 3.0.0 - 3.2.2 | High |
CVE-2025-53548 @clerk/backend is vulnerable to Insufficient Verification of Data Authenticity in versions 2.0.0 - 2.4.0. | 2.0.0 - 2.4.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
tslib Version 2.8.1 | — | — |
@clerk/shared Version ^4.40.0 | — | — |
standardwebhooks Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.