CVE-2024-22206: Clerk JavaScript

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.

Affected products

  • Clerk JavaScript: from 4.7.0, before 4.29.3 (fixed in 4.29.3)

Published 2024-01-12. Last modified 2026-06-17.