GHSA-vqx2-fgx2-5wq9: Official Clerk JavaScript SDKs: Middleware-based route protection bypass
createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers.
Sessions are not compromised and no existing user can be impersonated - the bypass only affects the middleware-level gating decision.
References
Code Behaviors & Features
Detect and mitigate GHSA-vqx2-fgx2-5wq9 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →