PT-2024-34883 · Next.Js+1 · Next.Js+1

Richardoc

·

Published

2024-11-05

·

Updated

2025-12-11

·

CVE-2024-51752

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AuthKit library for Next.js versions prior to 0.13.2
Description The issue concerns the logging of refresh tokens to the console when the debug flag is enabled. This flag is disabled by default. There are no known workarounds for this issue.
Recommendations For versions prior to 0.13.2, upgrade to version 0.13.2 to resolve the issue. As a temporary workaround, consider disabling the debug flag until the upgrade is applied.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-51752
GHSA-5WMG-9CVH-QW25

Affected Products

Authkit
Next.Js