{"id":"CVE-2024-51752","aliases":["GHSA-5wmg-9cvh-qw25"],"url":"https://o3.security/vulnerability/CVE-2024-51752","summary":"Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-nextjs","details":"The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.","published":"2024-11-05T19:16:41.831Z","modified":"2026-08-12T03:51:11.368474571Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@workos-inc/authkit-nextjs","fixedVersion":"0.13.2"}],"fix":{"url":"https://github.com/workos/authkit-nextjs/commit/15a332632f7560b03cc6d8cc8da24fd2ac931da7","label":"workos/authkit-nextjs@15a3326"},"references":[{"type":"WEB","url":"https://github.com/workos/authkit-nextjs/releases/tag/v0.13.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/51xxx/CVE-2024-51752.json"},{"type":"ADVISORY","url":"https://github.com/workos/authkit-nextjs/security/advisories/GHSA-5wmg-9cvh-qw25"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-51752"},{"type":"FIX","url":"https://github.com/workos/authkit-nextjs/commit/15a332632f7560b03cc6d8cc8da24fd2ac931da7"},{"type":"PACKAGE","url":"https://github.com/workos/authkit-nextjs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:11.368474571Z"}}