HomepageOkta logo

JWT Invalid Signature Validation in Auth0 Account Linking Extensions CVE-2025-46345 - Apr 30, 2025

View all security advisories

Description

Auth0 Account Linking Extensions versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization.

Affected versions

You are affected if you are using Auth0 Account Linking Extension versions 2.3.4 to 2.6.6.

Fix

Upgrade to the latest version 3.0.0 or greater.

Acknowledgments

Okta would like to thank Nykros ([email protected]) for their discovery.

CVE details

CVE ID

CVE-2025-46345

Published Date

2025-04-30

Vulnerability Type

JWT Signature Validation Bypass

CWE

CWE-347 - Improper Verification of Cryptographic Signature

CVSS v4

Score: 6.9 Vector string: https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References

JWT Invalid Signature Validation

For more information, see Auth0 Account Linking Rules Resolution and/or Auth0 Account Linking Actions Resolution.