PT-2025-62937 · Npm · @Clerk/Clerk-Js

Publicado

2025-11-20

·

Atualizado

2025-11-20

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
An issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.

Exploit

Correção

IDOR

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-3MM3-WFPV-Q85G

Produtos afetados

@Clerk/Clerk-Js