OktaOKTA-0IICB6P
Improper Validation of Query Parameters in Auth0 Next.js SDK CVE-2025-67716 - Dec 10, 2025
UnratedCVE-2025-67716 · Published Dec 10, 2025
An input-validation flaw in the returnTo parameter in the Auth0 Next.js SDK could allow attackers to inject unintended OAuth query parameters into the Auth0 authorization request. To remediate, upgrade Auth0/nextjs-auth0 version to v4.13.0
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 1 | Insufficient Entropy in Cookie Encryption in Auth0 Symfony SDK CVE-2026-34236 - Apr 1... | Unrated | No fix yet |
| Dec 102025 | Improper Request Caching Lookup in the Auth0 Next.js SDK CVE-2025-67490 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Improper Memory Cleanup in the Okta Java SDK CVE-2025-66033 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 102025 | Race condition in the Okta Java SDK CVE-2025-67505 - Dec 10, 2025 | Unrated | No fix yet |
| Dec 42025 | Improper HMAC Signature Verification in auth0/node-jws CVE-2025-65945 - Dec 4, 2025 | Unrated | No fix yet |
| Oct 12025 | Improper File Type Handling in Bulk User Import in Auth0 Wordpress plugin CVE-2025-58769... | Unrated | No fix yet |