The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HAuth0 Auth0.js
APPAuth0< 9.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2018-6873CRITICAL9.8PL ✓same product
Auth0 auth0.js — brak walidacji audience w JWT umożliwia privilege escalation
CVE-2026-42280HIGH7.1same product
Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, t...
CVE-2020-15125HIGH7.7same product
In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the r...
CVE-2018-6874HIGH8.8same product
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
CVE-2017-17068HIGH7.5same product
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This...