Improper User Profile Information Exposure in Auth0.js JavaScript Library
CVE-2026-42280
7.1HIGH
What is CVE-2026-42280?
The Auth0.js client-side JavaScript library experiences a vulnerability where, under specific conditions, it may incorrectly return user profile information. This issue arises when a maliciously crafted invalid ID token is presented alongside a valid access token, potentially exposing sensitive user data. The issue persists in versions 8.11.0 to 9.32.0, but is resolved in version 10.0.0.
Affected Version(s)
auth0.js >= 8.11.0 , <= 9.32.0
