A user can reuse an expired session by controlling the x-workos-session header.
Patched in https://github.com/workos/authkit-nextjs/releases/tag/v0.4.2
{
"github_reviewed": true,
"cwe_ids": [
"CWE-294"
],
"github_reviewed_at": "2024-03-29T20:16:00Z",
"nvd_published_at": "2024-03-29T16:15:08Z",
"severity": "MODERATE"
}