{"id":"GHSA-jr3j-whm4-9wwm","summary":"Reflected XSS when using flashMessages or languageDictionary","details":"### Overview\n\nVersions before and including `11.30.0` are vulnerable to reflected XSS.  An attacker can execute arbitrary code when the library's\n- `flashMessage` feature is utilized and user input or data from URL parameters is incorporated into the `flashMessage`.\n- `languageDictionary` feature is utilized and user input or data from URL parameters is incorporated into the `languageDictionary`.\n\n### Am I affected?\nYou are affected by this vulnerability if you are using `auth0-lock` version `11.30.0` or lower and all of the following conditions apply:\n\n- You are utilizing `flashMessage` feature.\n- User input or data from URL parameters is incorporated into the `flashMessage`.\n\nAn example of a vulnerable snippet where query parameters are used to populate the `text` property of a `flashMessage`.\n```js\nvar params = new URLSearchParams(location.search);\nvar errorMessage = params.get('error__message');\nvar showParams = {};\n\nif (!!errorMessage === true) {\n  showParams.flashMessage = {\n    type: 'error',\n    text: 'We were unable to log you in. ' + errorMessage,\n  };\n}\n\nlock.show(showParams);\n```\n\nOR\n\n- You are utilizing `languageDictionary` feature.\n- User input or data from URL parameters is used in `languageDictionary` properties.\n\nAn example of a vulnerable snippet where query parameters are used to populate the `socialLoginInstructions` property of a `languageDictionary`.\n```js\nvar params = new URLSearchParams(location.search);\nvar instruction = params.get('instruction');\n\nvar options = {\n  languageDictionary: {\n    emailInputPlaceholder: \"something@youremail.com\",\n    title: \"title\",\n    socialLoginInstructions: instruction\n  },\n};\n\nvar lock = new Auth0LockPasswordless(\n    CLIENT_ID,\n    DOMAIN,\n    options\n);\n\nlock.show()\n```\n\n### How to fix that?\nUpgrade to version `11.30.1`.\n\n### Will this update impact my users?\nThe fix uses [DOMPurify](https://github.com/cure53/DOMPurify) to sanitise the `flashMessage` and `languageDictionary` inputs. If you are including inline JavaScript in these fields, like `script` tags or `onclick` attributes, these will be removed.","aliases":["CVE-2021-32641"],"modified":"2026-07-08T06:00:58.295148741Z","published":"2021-06-04T19:10:34Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-06-04T18:28:08Z","nvd_published_at":"2021-06-04T21:15:00Z","cwe_ids":["CWE-79"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/auth0/lock/security/advisories/GHSA-jr3j-whm4-9wwm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32641"},{"type":"WEB","url":"https://github.com/auth0/lock/commit/d139cf01c8234b07caf265e051f39d3eab08f7ed"},{"type":"WEB","url":"https://github.com/auth0/lock/releases/tag/v11.30.1"}],"affected":[{"package":{"name":"auth0-lock","ecosystem":"npm","purl":"pkg:npm/auth0-lock"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.30.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-jr3j-whm4-9wwm/GHSA-jr3j-whm4-9wwm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}