CVE-2025-53548 Details
Description
Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. The issue was resolved in @clerk/backend 2.4.0.
A vulnerability exists in Clerk's user management libraries that allows applications to accept improperly signed webhook events. This issue affects several Clerk packages, including '@clerk/backend', '@clerk/astro', '@clerk/express', '@clerk/fastify', '@clerk/nextjs', '@clerk/nuxt', '@clerk/react-router', '@clerk/remix', and '@clerk/tanstack-react-start'. The vulnerability arises when the 'verifyWebhook()' helper is used to validate incoming Clerk webhooks, leading to the acceptance of malformed webhook signatures.
The vulnerability has been patched in all affected Clerk packages. Users should upgrade to the latest version of the specific package they are using. If an upgrade is not possible, webhooks can be verified manually according to the Clerk documentation on webhook protection.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2025CISA-ADP
Assessed Jul 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/clerk/javascript/security/advisories/GHSA-9mp4-77wg-rwx9 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| @clerk/backend | All versions |
CPE
Remediation
| |
| @clerk/astro | All versions |
CPE
Remediation
| |
| @clerk/express | All versions |
CPE
Remediation
| |
| @clerk/fastify | All versions |
CPE
Remediation
| |
| @clerk/nextjs | All versions |
CPE
Remediation
| |
| @clerk/nuxt | All versions |
CPE
Remediation
| |
| @clerk/react-router | All versions |
CPE
Remediation
| |
| @clerk/remix | All versions |
CPE
Remediation
| |
| @clerk/tanstack-react-start | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2025 | New CVE Received | [email protected] |
Volerion