Workos provides authentication and identity infrastructure for web applications, with its observed vulnerability footprint centered on the AuthKit Next.js integration product. The durable exposure pattern reflects challenges around session and credential handling: authentication bypass through capture-replay, sensitive information leakage into logs, and use of caches retaining sensitive data, all classes that reflect the session-state and token-management demands of authentication libraries. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Workos over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64762CRITICAL The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In authkit-nextjs version 2.11.0 and belo | Nov 21, 2025 | 9.1 | 29 | NO | NO |
CVE-2024-29901HIGH The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js.
A user can reuse an expired session by controlling t | Mar 29, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-51752MEDIUM The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are l | Nov 5, 2024 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Workos.
Media articles that mention a CVE ID that affects a product developed by Workos — matched by CVE ID, not by vendor name.