GHSA-3mm3-wfpv-q85g
MODERATECVE-2025-63700An issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.
- Affected
- <= 5.88.0
- Fixed in
- not stated
- Weakness
- CWE-290
- Published
- 2025-11-20
- Source
- github