CVE-2025-64762 is a critical vulnerability affecting AuthKit for Next.js versions 2.11.0 and below, where authenticated responses lack anti-caching headers. This flaw can lead to session tokens being cached by CDNs and subsequently exposed to unauthorized users, though Next.js applications on Vercel are generally unaffected unless CDN caching is manually enabled. With a CVSS score of 9.1 (CRITICAL), the vulnerability is easily exploitable over the network with high impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, but it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.1CPE matchmatch criteria | cpe:2.3:a:workos:authkit-nextjs:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.