{"id":"GHSA-8r88-6cj9-9fh5","summary":"auth-js Vulnerable to Insecure Path Routing from Malformed User Input","details":"### Impact\nThe library functions `getUserById`, `deleteUser`, `updateUserById`, `listFactors` and `deleteFactor` did not require the user supplied values to be valid UUIDs. This could lead to a URL path traversal, resulting in the wrong API function being called.\n\nImplementations that follow security best practice and validate user controlled inputs, such as the `userId` are not affected by this.\n\n### Patches\nStrict value checks have been added to all affected functions. These functions now require that the `userId` and `factorId` parameters MUST be valid UUID (v4).\n\n**Patched version:** \u003e= 2.69.1\n\n### Workarounds\nImplementations that follow security best practice and validate user controlled inputs, such as the `userId` are not affected by this. It is recommended that users of the auth-js library always follow security best practice and validate all inputs, before passing these to other functions or libraries.\n\n### References\nhttps://github.com/supabase/auth-js/pull/1063","aliases":["CVE-2025-48370"],"modified":"2026-05-05T18:18:39.323414Z","published":"2025-05-27T18:00:17Z","database_specific":{"nvd_published_at":"2025-05-27T16:15:32Z","cwe_ids":["CWE-22"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2025-05-27T18:00:17Z"},"references":[{"type":"WEB","url":"https://github.com/supabase/auth-js/security/advisories/GHSA-8r88-6cj9-9fh5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48370"},{"type":"WEB","url":"https://github.com/supabase/auth-js/pull/1063"},{"type":"WEB","url":"https://github.com/supabase/auth-js/commit/1bcb76e479e51cd9bca2d7732d0bf3199e07a693"},{"type":"PACKAGE","url":"https://github.com/supabase/auth-js"}],"affected":[{"package":{"name":"@supabase/auth-js","ecosystem":"npm","purl":"pkg:npm/%40supabase/auth-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.70.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.69.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-8r88-6cj9-9fh5/GHSA-8r88-6cj9-9fh5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}]}