{"id":"GHSA-954c-jjx6-cxv7","summary":"Reflected XSS from the callback handler's error query parameter","details":"### Overview\n\nVersions before and including `1.4.1` are vulnerable to reflected XSS.  An attacker can execute arbitrary code by providing an XSS payload in the `error` query parameter which is then processed by the callback handler as an error message.\n\n### Am I affected?\nYou are affected by this vulnerability if you are using `@auth0/nextjs-auth0` version `1.4.1` or lower **unless** you are using custom error handling that does not return the error message in an HTML response.\n\n### How to fix that?\nUpgrade to version `1.4.2`.\n\n### Will this update impact my users?\nThe fix adds basic HTML escaping to the error message and it should not impact your users.\n\n### Credit\n\nhttps://github.com/inian\nhttps://github.com/git-ishanpatel","aliases":["CVE-2021-32702"],"modified":"2026-07-08T06:29:07.810465813Z","published":"2021-06-28T16:46:41Z","database_specific":{"github_reviewed_at":"2021-06-25T15:38:26Z","nvd_published_at":"2021-06-25T17:15:00Z","cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-954c-jjx6-cxv7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32702"},{"type":"WEB","url":"https://github.com/auth0/nextjs-auth0/commit/6996e2528ceed98627caa28abafbc09e90163ccf"},{"type":"WEB","url":"https://www.npmjs.com/package/@auth0/nextjs-auth0"}],"affected":[{"package":{"name":"@auth0/nextjs-auth0","ecosystem":"npm","purl":"pkg:npm/%40auth0/nextjs-auth0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-954c-jjx6-cxv7/GHSA-954c-jjx6-cxv7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"}]}