We found results for “”
CVE-2025-67716
Good to know:
Date: December 10, 2025
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-validation flaw in the returnTo parameter, which could allow attackers to inject unintended OAuth query parameters into the Auth0 authorization request. Successful exploitation may result in tokens being issued with unintended parameters. This issue is fixed in version 4.13.0.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Incomplete List of Disallowed Inputs
CWE-184Top Fix
Upgrade Version
Upgrade to version @auth0/nextjs-auth0 - 4.13.0;https://github.com/auth0/nextjs-auth0.git - v4.13.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | REQUIRED |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


