CVE-2025-63700

An issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.
Configurations

No configuration.

History

20 Nov 2025, 22:16

Type Values Removed Values Added
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

20 Nov 2025, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-20 19:16

Updated : 2025-11-21 15:13


NVD link : CVE-2025-63700

Mitre link : CVE-2025-63700

CVE.ORG link : CVE-2025-63700


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing