@auth0/nextjs-auth0@0.16.1 vulnerabilities

Next.js SDK for signing in with Auth0

Direct Vulnerabilities

Known vulnerabilities in the @auth0/nextjs-auth0 package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Information Exposure

@auth0/nextjs-auth0 is a Next.js SDK for signing in with Auth0

Affected versions of this package are vulnerable to Information Exposure as certain returnTo parameter values aren't filtered from the login URL, which exposes the application to an open redirect vulnerability.

How to fix Information Exposure?

Upgrade @auth0/nextjs-auth0 to version 1.6.2 or higher.

<1.6.2
  • M
Cross-site Scripting (XSS)

@auth0/nextjs-auth0 is a Next.js SDK for signing in with Auth0

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the error query parameter.

How to fix Cross-site Scripting (XSS)?

Upgrade @auth0/nextjs-auth0 to version 1.4.1 or higher.

<1.4.1