Package impact
npm / auth0-js
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17068 | high | 7.5 | 7.5 | 9y ago | auth0-js Privilege Escalation Vulnerability | |||
| CVE-2026-42280 | high | 7.1 | 7.1 | 2d ago | Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token… | |||
| CVE-2020-5263 | unknown | — | — | 6y ago | Information disclosure through error object in auth0.js | |||
| CVE-2018-6874 | unknown | — | — | 8y ago | Cross-Site Request Forgery (CSRF) in Auth0 | |||
| CVE-2018-7307 | unknown | — | — | 8y ago | Auth0-js bypasses CSRF checks |