{"id":"CVE-2024-51753","aliases":["GHSA-v2qh-f584-6hj8"],"url":"https://o3.security/vulnerability/CVE-2024-51753","summary":"Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-remix","details":"The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.4.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.","published":"2024-11-05T19:14:47.097Z","modified":"2026-07-15T01:49:03.554885803Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@workos-inc/authkit-remix","fixedVersion":"0.4.1"}],"fix":{"url":"https://github.com/workos/authkit-remix/commit/32d5bcd54c795c1e2a3204f8e3977ab9ad57ec06","label":"workos/authkit-remix@32d5bcd"},"references":[{"type":"WEB","url":"https://github.com/workos/authkit-remix/releases/tag/v0.4.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/51xxx/CVE-2024-51753.json"},{"type":"ADVISORY","url":"https://github.com/workos/authkit-remix/security/advisories/GHSA-v2qh-f584-6hj8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-51753"},{"type":"FIX","url":"https://github.com/workos/authkit-remix/commit/32d5bcd54c795c1e2a3204f8e3977ab9ad57ec06"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:03.554885803Z"}}