npm package
@workos-inc/authkit-nextjs
pkg:npm/%40workos-inc/authkit-nextjs
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-64762 | — | < 2.11.1 | 2.11.1 | Nov 21, 2025 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In authkit-nextjs version 2.11.0 and below, authenticated responses do not defensively apply anti-caching headers. In environments where CDN | ||
| CVE-2024-51752 | — | < 0.13.2 | 0.13.2 | Nov 5, 2024 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patc | ||
| CVE-2024-29901 | — | < 0.4.2 | 0.4.2 | Mar 29, 2024 | The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2. |
- CVE-2025-64762Nov 21, 2025affected < 2.11.1fixed 2.11.1
The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In authkit-nextjs version 2.11.0 and below, authenticated responses do not defensively apply anti-caching headers. In environments where CDN
- CVE-2024-51752Nov 5, 2024affected < 0.13.2fixed 0.13.2
The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. This issue has been patc
- CVE-2024-29901Mar 29, 2024affected < 0.4.2fixed 0.4.2
The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2.