PT-2025-62937 · Npm · @Clerk/Clerk-Js

Published

2025-11-20

·

Updated

2025-11-20

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
An issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.

Exploit

Fix

IDOR

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-3MM3-WFPV-Q85G

Affected Products

@Clerk/Clerk-Js