CVE-2025-46345: Auth0 Account Link Extension JWT Invalid Signature Validation
Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization. This issue has been patched in versions 2.6.7, 2.7.0, and 3.0.0. It is recommended to upgrade to version 3.0.0 or greater.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46345?
CVE-2025-46345 is considered a high severity vulnerability due to the risk of unauthorized access to user information.
How do I fix CVE-2025-46345?
To fix CVE-2025-46345, upgrade Auth0 Account Link Extension to version 2.6.7 or later where the JWT signature verification is implemented.
What versions are affected by CVE-2025-46345?
CVE-2025-46345 affects Auth0 Account Link Extension versions from 2.3.4 to 2.6.6.
What is the impact of CVE-2025-46345?
The impact of CVE-2025-46345 allows attackers to exploit the vulnerability to access user data without proper authorization.
Who is affected by CVE-2025-46345?
Any user or organization using Auth0 Account Link Extension versions 2.3.4 to 2.6.6 is affected by CVE-2025-46345.