Skip to content

Vulnerability on [email protected] #13161

@joyarzun

Description

@joyarzun

Environment

  System:
    OS: macOS 15.5
    CPU: (14) arm64 Apple M3 Max
    Memory: 82.19 MB / 36.00 GB
    Shell: 5.9 - /bin/zsh
  Binaries:
    Node: 22.5.1 - /opt/homebrew/bin/node
    Yarn: 1.22.22 - ~/.npm_packages/bin/yarn
    npm: 10.8.2 - /opt/homebrew/bin/npm
  Browsers:
    Chrome: 138.0.7204.184
    Safari: 18.5
  npmPackages:
    next: 15.4.4 => 15.2.3
    next-auth: ^4.24.11 => 4.24.11
    react: ^18.3.1 => 18.3.1```


### Reproduction URL

no-url.com

### Describe the issue

CVE Details
Published: Aug 1, 2025
The jose versions through 6.0.10 was discovered to contain weak encryption.

[Reference](https://github.com/advisories/GHSA-m523-xm42-q7ff)

### How to reproduce

npm install next-auth then scan with checkmarkx

### Expected behavior

scan result without issues

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinginvalid reproductionThe issue did not have a detectable valid reproduction URLtriageUnseen or unconfirmed by a maintainer yet. Provide extra information in the meantime.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions