Bugcrowd submission demo — Auth0 Next.js SDK
Deliberately vulnerable demo application, standing up @auth0/nextjs-auth0@4.26.0 with Auth0’s shipped examples/with-cte route, for one Bugcrowd submission.
No real data, no real Auth0 tenant. The authorization server is a local mock and every token it issues is a fixed sentinel string. Nothing here is a production system and nothing here is worth attacking.
Reachable endpoints: POST /api/cte, GET /auth/login.
Reported by @abiusx. This host is torn down when the submission resolves.