Executive brief
Auth0 Lock is a widely-used authentication UI widget used by applications to handle user sign-up and login. When the "additional signup fields" feature is enabled, malicious users can inject unvalidated HTML code that gets stored in user metadata and rendered in verification emails, potentially allowing attackers to send phishing emails or trick users into clicking malicious links that appear to come from legitimate sources.
Technical details
This is a cross-site scripting (CWE-79) vulnerability in the additional signup fields feature of Auth0 Lock. The vulnerability exists because user input provided in additional signup fields is not properly sanitized before being stored in the service's user_metadata payload. When verification emails are generated, this unsanitized metadata (specifically the name property) is rendered directly into the email template without HTML escaping. An attacker can craft a malicious signup request injecting HTML/JavaScript into these fields, which is then delivered to victims via email, potentially enabling phishing attacks or credential theft. The fix, released in version 11.33.0, strips HTML tags from user input in additional signup fields on the signup tab.
Affected products
- Auth0 Lock 11.32.2 and earlier
Timeline
- 2022-05-05: disclosed
- 2022-05-24: advisory
- 2022-05-24: patched: Version 11.33.0 released