CVE-2019-20174: AUTH0 Lock
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
Affected products
- AUTH0 Lock: before 11.21.0 (fixed in 11.21.0)
Published 2020-02-03. Last modified 2026-06-17.