HIGHnpm

Clerk has an authorization bypass when combining organization, billing, or reverification checks

Clerk has an authorization bypass when combining organization, billing, or reverification checks

CVE-2026-42349Published 4 months agoUpdated 5 days agoSource: OSV

Affected packages

  • @clerk/astro
  • @clerk/backend
  • @clerk/chrome-extension
  • @clerk/clerk-expo
  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/expo
  • @clerk/express
  • @clerk/fastify
  • @clerk/hono
  • @clerk/nextjs
  • @clerk/nuxt
  • @clerk/react
  • @clerk/react-router
  • @clerk/shared
  • @clerk/tanstack-react-start
  • @clerk/vue

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Clerk has an authorization bypass when combining organization, billing, or reverification checks | HackTribune