Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w24r-5266-9c3c | Clerk has an authorization bypass when combining organization, billing, or reverification checks |
Thu, 14 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clerk
Clerk astro Clerk backend Clerk chrome-extension Clerk clerk-expo Clerk clerk-react Clerk expo Clerk express Clerk fastify Clerk hono Clerk javascript Clerk nextjs Clerk nuxt Clerk react Clerk react-router Clerk shared Clerk tanstack-react-start Clerk vue |
|
| Vendors & Products |
Clerk
Clerk astro Clerk backend Clerk chrome-extension Clerk clerk-expo Clerk clerk-react Clerk expo Clerk express Clerk fastify Clerk hono Clerk javascript Clerk nextjs Clerk nuxt Clerk react Clerk react-router Clerk shared Clerk tanstack-react-start Clerk vue |
Mon, 11 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who does not satisfy the full set of requested conditions. This call shape can be bypassed if certain conditions are met: a has() or auth.protect() call that combines a reverification check with any of role, permission, feature, or plan, or that combines a billing check (feature or plan) with a role or permission check. This vulnerability is fixed in @clerk/clerk-js 5.125.10 and 6.7.5. | |
| Title | Clerk: Authorization bypass when combining organization, billing, or reverification checks | |
| Weaknesses | CWE-754 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T18:19:38.735Z
Reserved: 2026-04-26T13:26:14.515Z
Link: CVE-2026-42349
Updated: 2026-05-14T18:19:17.030Z
Status : Awaiting Analysis
Published: 2026-05-11T17:16:33.147
Modified: 2026-05-14T19:16:35.777
Link: CVE-2026-42349
No data.
OpenCVE Enrichment
Updated: 2026-05-12T09:22:55Z
Github GHSA