Improper User Profile Information Exposure in Auth0.js JavaScript Library
CVE-2026-42280

7.1HIGH

Key Information:

Vendor

Auth0

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-42280?

The Auth0.js client-side JavaScript library experiences a vulnerability where, under specific conditions, it may incorrectly return user profile information. This issue arises when a maliciously crafted invalid ID token is presented alongside a valid access token, potentially exposing sensitive user data. The issue persists in versions 8.11.0 to 9.32.0, but is resolved in version 10.0.0.

Affected Version(s)

auth0.js >= 8.11.0 , <= 9.32.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.