All 3 CVE vulnerabilities found in authkit-nextjs, with AI-generated Chinese analysis, references, and POCs.
Vendor: workos
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2025-64762 | authkit-nextjs may let session cookies be cached in CDNs CWE-524 | 4.2 | - | 2025-11-21 |
| CVE-2024-51752 | Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-nextjs CWE-532 | 5.3AI | MediumAI | 2024-11-05 |
| CVE-2024-29901 | @workos-inc/authkit-nextjs session replay vulnerability CWE-294 | 4.8 | Medium | 2024-03-29 |
All 3 known CVE vulnerabilities affecting authkit-nextjs with full Chinese analysis, references, and POCs where available.