Security: clerk/javascript
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Authorization bypass when combining organization, billing, or reverification checksGHSA-w24r-5266-9c3c published
Apr 22, 2026 by nikosdouvlisHigh -
Middleware-based route protection bypassGHSA-vqx2-fgx2-5wq9 published
Apr 15, 2026 by nikosdouvlisCritical -
SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended hostGHSA-gjxx-92w9-8v8f published
Mar 26, 2026 by nikosdouvlisHigh -
@clerk/backend: Webhook verification vulnerabilityGHSA-9mp4-77wg-rwx9 published
Jul 9, 2025 by brkalowHigh -
@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)GHSA-q6w5-jg5q-47vg published
Jan 12, 2024 by zythosecCritical