CVE-2025-48370 - CVE House
Back to Database
Status published Low CVE-2025-48370

auth-js Vulnerable to Insecure Path Routing from Malformed User Input

Vulnerability Description

auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs. This could lead to a URL path traversal, resulting in the wrong API function being called. Implementations that follow security best practice and validate user controlled inputs, such as the userId are not affected by this. This issue has been patched in version 2.70.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48370

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

auth-js
Vulnerable Versions:
< 2.70.0

Timeline

Official Publish: May 27th, 2025
Last Modified: April 27th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)