Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/@clerk/nextjs — 4 CVEs · VulnScope
pkg:npm/
@clerk/nextjs
4 total CVEs
CRITICAL
2
HIGH
2
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.1
CVE-2026-41248
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
>= 5.0.0, < 5.7.6
CRITICAL
9.0
CVE-2024-22206
@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)
>= 4.7.0, < 4.29.3
HIGH
8.1
CVE-2026-42349
Clerk has an authorization bypass when combining organization, billing, or reverification checks
>= 6.0.0, < 6.39.3
HIGH
7.5
@clerk/backend Performs Insufficient Verification of Data Authenticity
>= 6.2.10, < 6.23.3
CVE-2025-53548