CVE-2018-6873: AUTH0 AUTH0.JS
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
Affected products
- AUTH0 AUTH0.JS: up to and including 8.10.1
Published 2018-04-04. Last modified 2026-06-17.