Junglewise Threat Intelligence

CVE-2025-53548: Clerk webhook verifyWebhook insufficient signature verification

CVE-2025-53548 · Severity: low · CVSS 3.1 · Published 2025-07-09

Technologies: Clerk Backend, Clerk Nextjs. Vendors: npm, Clerk.

Executive brief

Clerk's webhook verification helper accepts improperly signed webhook events from the Clerk authentication service. An attacker can forge webhook messages (such as user creation, deletion, or session events) without a valid signature, enabling unauthorized account manipulation and session hijacking in applications relying on webhook events for security-critical decisions.

Technical details

The verifyWebhook() helper in multiple Clerk SDKs (backend, nextjs, remix, express, fastify, nuxt, astro, react-router, tanstack-react-start) failed to properly parse and validate webhook request signatures. The vulnerability is rooted in CWE-345 (Insufficient Verification of Data Authenticity): the helper did not correctly compare received signatures against the expected HMAC signature derived from the webhook payload. An unauthenticated, network-accessible attacker can send forged webhook events to applications without providing a valid signature. The fix (implemented in @clerk/backend 2.4.0 and corresponding versions in dependent packages) corrects signature parsing and comparison logic. No user interaction is required; exploitation occurs during normal webhook processing.

Affected products

  • Clerk @clerk/backend 2.0.0 to 2.3.x
  • Clerk @clerk/nextjs 6.2.10 to 6.23.2
  • Clerk @clerk/remix 4.8.0 to 4.8.4
  • Clerk @clerk/express 1.6.0 to 1.7.3
  • Clerk @clerk/fastify 2.3.0 to 2.4.3
  • Clerk @clerk/nuxt 1.7.0 to 1.7.4
  • Clerk @clerk/astro 2.9.0 to 2.10.1
  • Clerk @clerk/react-router 1.5.0 to 1.6.3
  • Clerk @clerk/tanstack-react-start 0.16.0 to 0.18.2

Timeline

  • 2025-07-09: disclosed: Vulnerability published in GHSA and CVE databases
  • 2025-07-09: patched: Patches released across all affected Clerk packages

References

Related threats