Clerk is an authentication and user-management platform whose vulnerability profile centers on its core JavaScript library and clerk.io service, with recurring issues rooted in authorization and access-control mechanisms. The observed weakness classes—including authorization bypass through user-controlled keys, improper access control, and flawed authentication or condition-checking logic—reflect the sensitivity of identity-layer implementations where validation gaps can cascade across dependent applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clerk over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42349HIGH Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk | May 11, 2026 | 8.1 | 29 | NO | NO |
CVE-2024-22206CRITICAL Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vul | Jan 12, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clerk.
Media articles that mention a CVE ID that affects a product developed by Clerk — matched by CVE ID, not by vendor name.