CVE-2025-63700: High severity Clerk Clerk-js vulnerability
An issue was discovered in Clerk-js 5.88.0 allowing attackers to bypass the OAuth authentication flow by manipulating the request at the OTP verification stage.
Other sources
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63700?
CVE-2025-63700 has been assessed as a high-severity vulnerability due to its potential impact on the authentication process.
How do I fix CVE-2025-63700?
To fix CVE-2025-63700, update Clerk-js to version 5.88.1 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2025-63700?
CVE-2025-63700 is an authentication bypass vulnerability occurring during the OTP verification stage.
Which software versions are affected by CVE-2025-63700?
CVE-2025-63700 affects Clerk-js versions up to and including 5.88.0.
How can attackers exploit CVE-2025-63700?
Attackers can exploit CVE-2025-63700 by manipulating requests during the OTP verification process to bypass OAuth authentication.