@kinde-oss/kinde-auth-nextjs is vulnerable to Storage of Sensitive Information in a Cookie
40
Medium Risk
Affected versions of the package are vulnerable to storage of sensitive information in a cookie. The API access token is stored in the cookie under the name kinde_api_access_token, potentially exposing it to unauthorized access.
You are affected if you are using a version that falls within the vulnerable range.
@kinde-oss/kinde-auth-nextjs is vulnerable to Storage of Sensitive Information in a Cookie in versions 1.8.19 - 1.10.1 and 2.0.0 - 2.3.8.
Upgrade the @kinde-oss/kinde-auth-nextjs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant