CVE-2024-51752: Workos Authkit-Nextjs

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

  • Workos Authkit-Nextjs: before 0.13.2 (fixed in 0.13.2)

Published 2024-11-05. Last modified 2026-06-17.