Home / Companies / Clerk / Blog / Post Details
Content Deep Dive

Middleware-based route protection bypass

Blog post from Clerk

Post Details
Company
Date Published
Author
Colin Sidoti
Word Count
51
Language
English
Hacker News Points
-
Summary

A CVE has been released for a vulnerability that allows a route protection bypass in applications using the createRouteMatcher in middleware or proxy, specifically impacting frameworks such as Next, Nuxt, or Astro. Users are advised to upgrade their systems immediately to mitigate this security risk, with detailed upgrade instructions provided in the accompanying security advisory. For further inquiries or issues, users are encouraged to contact support for assistance.