
🚨 High - Auth0 auth0-js improper permission checking (CVE-2026-42280) Improper validation may return user profile data when a crafted invalid ID token is used with a valid access token, leading to unauthorized information disclosure. 👉 Affects 8.11.0–9.32.0 — update to 10.0.0+
Post summary
Auth0 auth0-js CVE-2026-42280 allows unauthorized user profile disclosure via improper validation; affected versions 8.11.0–9.32.0 are fixed in 10.0.0+.
