Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3200 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-5wmg-9cvh-qw25 | @workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled |
Thu, 11 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Workos authkit-nextjs
|
|
| CPEs | cpe:2.3:a:workos:authkit-nextjs:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Workos authkit
|
Workos authkit-nextjs
|
Wed, 10 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Workos
Workos authkit |
|
| CPEs | cpe:2.3:a:workos:authkit:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Workos
Workos authkit |
|
| Metrics |
cvssV3_1
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 05 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Nov 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Title | Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-nextjs | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-05T20:15:07.923Z
Reserved: 2024-10-31T14:12:45.791Z
Link: CVE-2024-51752
Updated: 2024-11-05T20:15:03.842Z
Status : Analyzed
Published: 2024-11-05T20:15:15.167
Modified: 2025-12-11T17:45:40.303
Link: CVE-2024-51752
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA