JWT Invalid Signature Validation in Auth0 Account Linking Extensions CVE-2025-46345 - Apr 30, 2025
Description
Auth0 Account Linking Extensions versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization.
Affected versions
You are affected if you are using Auth0 Account Linking Extension versions 2.3.4 to 2.6.6.
Fix
Upgrade to the latest version 3.0.0 or greater.
Acknowledgments
Okta would like to thank Nykros ([email protected]) for their discovery.
CVE details
CVE ID | |
Published Date | 2025-04-30 |
Vulnerability Type | JWT Signature Validation Bypass |
CWE | CWE-347 - Improper Verification of Cryptographic Signature |
CVSS v4 | Score: 6.9 Vector string: https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
References
JWT Invalid Signature Validation
For more information, see Auth0 Account Linking Rules Resolution and/or Auth0 Account Linking Actions Resolution.