Internal package utils used by the Clerk SDKs
92%
Total Score
63
100
100
95
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-42349 @clerk/shared is vulnerable to Improper Check for Unusual or Exceptional Conditions in versions 3.0.0 - 3.47.4 and 4.0.0 - 4.8.2. | 3.0.0 - 3.47.44.0.0 - 4.8.2 | High |
AIKIDO-2024-10212 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @clerk/shared is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 2.4.5. | 0.0.1 - 2.4.5 | Low |
| Dependency | Last Release | Score |
|---|---|---|
dequal Version 2.0.3 | — | — |
std-env Version ^3.9.0 | — | — |
js-cookie Version 3.0.7 | — | — |
glob-to-regexp Version 0.4.1 | — | — |
@tanstack/query-core Version ^5.100.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant