Bugcrowd submission demo — Auth0 Next.js SDK

Deliberately vulnerable demo application, standing up @auth0/nextjs-auth0@4.26.0 with Auth0’s shipped examples/with-cte route, for one Bugcrowd submission.

No real data, no real Auth0 tenant. The authorization server is a local mock and every token it issues is a fixed sentinel string. Nothing here is a production system and nothing here is worth attacking.

Reachable endpoints: POST /api/cte, GET /auth/login.

Reported by @abiusx. This host is torn down when the submission resolves.