Executive brief
Clerk's webhook verification helper accepts improperly signed webhook events from the Clerk authentication service. An attacker can forge webhook messages (such as user creation, deletion, or session events) without a valid signature, enabling unauthorized account manipulation and session hijacking in applications relying on webhook events for security-critical decisions.
Technical details
The verifyWebhook() helper in multiple Clerk SDKs (backend, nextjs, remix, express, fastify, nuxt, astro, react-router, tanstack-react-start) failed to properly parse and validate webhook request signatures. The vulnerability is rooted in CWE-345 (Insufficient Verification of Data Authenticity): the helper did not correctly compare received signatures against the expected HMAC signature derived from the webhook payload. An unauthenticated, network-accessible attacker can send forged webhook events to applications without providing a valid signature. The fix (implemented in @clerk/backend 2.4.0 and corresponding versions in dependent packages) corrects signature parsing and comparison logic. No user interaction is required; exploitation occurs during normal webhook processing.
Affected products
- Clerk @clerk/backend 2.0.0 to 2.3.x
- Clerk @clerk/nextjs 6.2.10 to 6.23.2
- Clerk @clerk/remix 4.8.0 to 4.8.4
- Clerk @clerk/express 1.6.0 to 1.7.3
- Clerk @clerk/fastify 2.3.0 to 2.4.3
- Clerk @clerk/nuxt 1.7.0 to 1.7.4
- Clerk @clerk/astro 2.9.0 to 2.10.1
- Clerk @clerk/react-router 1.5.0 to 1.6.3
- Clerk @clerk/tanstack-react-start 0.16.0 to 0.18.2
Timeline
- 2025-07-09: disclosed: Vulnerability published in GHSA and CVE databases
- 2025-07-09: patched: Patches released across all affected Clerk packages