3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether @clerk/express is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.1
CVE-2026-42349
Clerk has an authorization bypass when combining organization, billing, or reverification checks
HIGH 7.4
CVE-2026-34076
Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host
HIGH 7.5
CVE-2025-53548
@clerk/backend Performs Insufficient Verification of Data Authenticity
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes