Clerk SDK for NextJS
92%
Total Score
63
100
100
95
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-41248 @clerk/nextjs is vulnerable to Interpretation Conflict in versions 5.0.0 - 5.7.6, 6.0.0-snapshot.vb87a27f - 6.39.2 and 7.0.0 - 7.2.1. | 5.0.0 - 5.7.66.0.0-snapshot.vb87a27f - 6.39.27.0.0 - 7.2.1 | Critical |
AIKIDO-2024-10213 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @clerk/nextjs is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 5.2.14. | 0.0.1 - 5.2.14 | Low |
CVE-2024-22206 @clerk/nextjs is vulnerable to Improper Access Control in versions 4.7.0 - 4.29.3. | 4.7.0 - 4.29.3 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
tslib Version 2.8.1 | — | — |
server-only Version 0.0.1 | — | — |
@clerk/react Version ^6.7.2 | — | — |
@clerk/shared Version ^4.14.0 | — | — |
@clerk/backend Version ^3.4.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant