CVE-2026-41248
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 4 assertions
{"product":"nuxt","vendor":"clerk","versions":[{"status":"affected","version":">= 1.1.0, < 1.13.28"},{"status":"affected","version":">= 2.0.0, < 2.2.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/affected/2
{"product":"nextjs","vendor":"clerk","versions":[{"status":"affected","version":">= 5.0.0, < 5.7.6"},{"status":"affected","version":">= 6.0.0-snapshot.vb87a27f, < 6.39.2"},{"status":"affected","version":">= 7.0.0, < 7.2.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/affected/1
{"product":"astro","vendor":"clerk","versions":[{"status":"affected","version":">= 0.0.1, < 1.5.7"},{"status":"affected","version":">= 2.0.0-snapshot.v20241206174604, <= 2.17.9"},{"status":"affected","version":">= 3.0.0, < 3.0.15"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/affected/0
{"product":"shared","vendor":"clerk","versions":[{"status":"affected","version":">= 2.20.17, < 2.22.1"},{"status":"affected","version":">= 3.0.0-canary.v20250225091530, < 3.47.4"},{"status":"affected","version":">= 4.0.0, < 4.8.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/affected/3
cwe · 2 assertions
{"cweId":"CWE-436","description":"CWE-436: Interpretation Conflict","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
4 source assertions{"product":"nuxt","vendor":"clerk","versions":[{"status":"affected","version":">= 1.1.0, < 1.13.28"},{"status":"affected","version":">= 2.0.0, < 2.2.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/affected/2
{"product":"nextjs","vendor":"clerk","versions":[{"status":"affected","version":">= 5.0.0, < 5.7.6"},{"status":"affected","version":">= 6.0.0-snapshot.vb87a27f, < 6.39.2"},{"status":"affected","version":">= 7.0.0, < 7.2.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/affected/1
{"product":"astro","vendor":"clerk","versions":[{"status":"affected","version":">= 0.0.1, < 1.5.7"},{"status":"affected","version":">= 2.0.0-snapshot.v20241206174604, <= 2.17.9"},{"status":"affected","version":">= 3.0.0, < 3.0.15"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/affected/0
{"product":"shared","vendor":"clerk","versions":[{"status":"affected","version":">= 2.20.17, < 2.22.1"},{"status":"affected","version":">= 3.0.0-canary.v20250225091530, < 3.47.4"},{"status":"affected","version":">= 4.0.0, < 4.8.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/affected/3
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-436","description":"CWE-436: Interpretation Conflict","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/problemTypes/1/descriptions/0
Source references
1 source assertion{"name":"https://github.com/clerk/javascript/security/advisories/GHSA-vqx2-fgx2-5wq9","tags":["x_refsource_CONFIRM"],"url":"https://github.com/clerk/javascript/security/advisories/GHSA-vqx2-fgx2-5wq9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c42c8003f9ce530ae6e7afabe0ccd2f4360a0b7aef978f0e8d1035ba0058b4a5 · sha256:c60c10d89254a060… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.