Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. The issue was resolved in @clerk/backend 2.4.0.
History

Wed, 09 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Jul 2025 17:30:00 +0000

Type Values Removed Values Added
Description Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. The issue was resolved in @clerk/backend 2.4.0.
Title @clerk/backend Performs Insufficient Verification of Data Authenticity
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-09T17:12:10.483Z

Updated: 2025-07-09T17:34:36.765Z

Reserved: 2025-07-02T15:15:11.516Z

Link: CVE-2025-53548

cve-icon Vulnrichment

Updated: 2025-07-09T17:34:28.635Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-09T18:15:24.157

Modified: 2025-07-10T13:17:30.017

Link: CVE-2025-53548

cve-icon Redhat

No data.