Insecure session management In @workos-inc/authkit-nextjs

Description

@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled

Impact

Refresh tokens are logged to the console when the disabled by default debug flag, is enabled.

Patches

Patched in https://github.com/workos/authkit-nextjs/releases/tag/v0.13.2

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions