VendorsAuth0auth0.jsall versions
Vulnerabilities

Auth0 auth0.js

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2018-6873
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
Published 2018-04-04 · Modified
9.8EPSS 0.022
CVE-2018-6874
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
Published 2018-04-04 · Modified
8.8EPSS 0.007
CVE-2018-7307
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
Published 2018-03-06 · Modified
8.8EPSS 0.005
CVE-2020-15125
Authorization header is not sanitized in an error object in auth0
Published 2020-07-29 · Modified
7.7EPSS 0.015
CVE-2017-17068
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback page with auth0.popup.callback().
Published 2017-12-06 · Modified
7.5EPSS 0.014
CVE-2026-42280
Improper Permission Checking in Auth.js SDK
Published 2026-05-27 · Analyzed
7.1EPSS 0.002
CVE-2020-5263
Information disclosure through error object
Published 2020-04-09 · Modified
5.5EPSS 0.009