Executive brief
The WorkOS AuthKit library for Next.js, used to manage user authentication and sessions, logs sensitive refresh tokens to the console when a debug flag is enabled. While this flag is off by default, developers who turn it on for troubleshooting could expose authentication credentials in application logs, potentially allowing unauthorized access to user accounts. The vulnerability has been patched in version 0.13.2.
Technical details
The vulnerability is classified as information disclosure (CWE-532). When the debug flag (disabled by default) is explicitly enabled by a developer or administrator, the library logs refresh tokens to the console output. This is an implementation flaw where sensitive tokens should never be logged, regardless of debug settings. The attack vector requires local access to application logs and the debug flag to be explicitly enabled, reducing immediate risk but creating a configuration-based exposure vector. An attacker with access to console logs or log aggregation systems could extract valid refresh tokens and use them to forge authenticated sessions. The fix, released in version 0.13.2, updated the logging strategy to exclude sensitive tokens from debug output.
Affected products
- WorkOS @workos-inc/authkit-nextjs < 0.13.2
Timeline
- 2024-11-05: disclosed: GHSA-5wmg-9cvh-qw25 published
- 2024-11-04: patched: Patched in v0.13.2