CVE-2025-67716
MEDIUMDescription
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through 4.12.1 contain an input-validation flaw in the returnTo parameter, which could allow attackers to inject unintended OAuth query parameters into the Auth0 authorization request. Successful exploitation may result in tokens being issued with unintended parameters. This issue is fixed in version 4.13.0.
Is your site exposed to CVE-2025-67716?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| auth0 | nextjs-auth0 |
References
Frequently Asked Questions
What is CVE-2025-67716? +
How severe is CVE-2025-67716? +
What products are affected by CVE-2025-67716? +
How do I check if I'm vulnerable to CVE-2025-67716? +
Related Vulnerabilities
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior …
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create …
Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise …
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the …