GHSA-w24r-5266-9c3c
HIGHCVE-2026-42349has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who does not satisfy the full set of requested conditions.
- Affected
- >=0.0.2, <0.1.16, >= 3.0.0, <= 3.47.4
- Fixed in
- 3.47.5
- Weakness
- CWE-754
- Published
- 2026-04-30
- Source
- osv