Clerk JS library
85%
Total Score
62
100
100
65
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-63700 @clerk/clerk-js is vulnerable to Authentication Bypass by Spoofing in versions 0.0.0 - 5.88.0. | 0.0.0 - 5.88.0 | High |
AIKIDO-2025-10556 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @clerk/clerk-js is vulnerable to Cross-site Scripting (XSS) in versions 4.0.0 - 5.82.0. | 4.0.0 - 5.82.0 | Medium |
AIKIDO-2024-10335 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @clerk/clerk-js is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 2.13.1 - 5.26.3. | 2.13.1 - 5.26.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
dequal Version 2.0.3 | — | — |
core-js Version 3.47.0 | — | — |
crypto-js Version ^4.2.0 | — | — |
@swc/helpers Version 0.5.21 | — | — |
@clerk/shared Version ^4.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant