A vulnerability was found in auth0 nextjs-auth0 up to 4.6.0 and classified as critical. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument Cache-Control leads to use of web browser cache containing sensitive information.
This vulnerability is handled as CVE-2025-48947. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.