Account Linking Vulnerability in Auth0 Extension
CVE-2025-46345
6.9MEDIUM
What is CVE-2025-46345?
The Auth0 Account Link Extension, designed for linking user accounts seamlessly, contains a vulnerability in versions 2.3.4 to 2.6.6. This issue arises because the extension fails to verify the signature of provided JSON Web Tokens (JWTs). An attacker could exploit this flaw by submitting a forged token, potentially gaining unauthorized access to sensitive user information. To mitigate this risk, users should upgrade to version 3.0.0 or later, where the vulnerability has been addressed and patched.
Affected Version(s)
auth0-account-link-extension >= 2.3.4, < 2.6.7
