A vulnerability has been found in clerk javascript, shared, backend, nextjs, -react, react, vue, astro, nuxt, -expo, expo, react-router, tanstack-react-start, chrome-extension, fastify, express and hono and classified as critical. This impacts an unknown function. This manipulation causes improper check for unusual conditions.

This vulnerability is handled as CVE-2026-42349. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.