CVE-2025-53548

Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. The issue was resolved in @clerk/backend 2.4.0.
Configurations

No configuration.

History

10 Jul 2025, 13:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 18:15

Updated : 2025-07-10 13:17


NVD link : CVE-2025-53548

Mitre link : CVE-2025-53548

CVE.ORG link : CVE-2025-53548


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity