Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8qjv-jj2q-x832 | Auth.js SDK has Improper Permission Checking |
Thu, 04 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:auth0:auth0.js:*:*:*:*:*:node.js:*:* |
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Auth0
Auth0 auth0.js |
|
| Vendors & Products |
Auth0
Auth0 auth0.js |
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is fixed in 10.0.0. | |
| Title | Improper Permission Checking in Auth.js SDK | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-28T15:36:56.102Z
Reserved: 2026-04-26T11:53:27.717Z
Link: CVE-2026-42280
Updated: 2026-05-28T15:36:51.445Z
Status : Analyzed
Published: 2026-05-27T15:16:27.753
Modified: 2026-06-17T10:47:37.527
Link: CVE-2026-42280
No data.
OpenCVE Enrichment
Updated: 2026-05-28T04:30:06Z
Github GHSA