Vulnerabilities (CVE)

Filtered by vendor Workos Subscribe
Filtered by product Authkit
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-51752 1 Workos 1 Authkit 2025-09-10 N/A 5.5 MEDIUM
The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-29901 1 Workos 1 Authkit 2025-05-07 N/A 4.8 MEDIUM
The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2.