CVE-2024-51752
Severity CVSS v4.0:
LOW
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
05/11/2024
Last modified:
11/12/2025
Description
The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patched in version 0.13.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:workos:authkit-nextjs:*:*:*:*:*:node.js:*:* | 0.13.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



