CVE-2022-31186
JavaScript vulnerability analysis and mitigation

Overview

An information disclosure vulnerability exists in next-auth before versions 4.10.2 and 3.29.9. The vulnerability allows an attacker with log access privilege to obtain excessive information such as an identity provider's secret in the log, which is thrown during OAuth error handling (NextAuth Advisory).

Technical details

The vulnerability occurs when debug logging is enabled, causing sensitive information like provider secrets to be exposed in error logs during OAuth error handling. The issue affects versions prior to 4.10.2 and 3.29.9 of the next-auth package. The vulnerability has been assigned a CVSS score of 3.3 (Low), with attack vector being Local, attack complexity Low, and requiring Low privileges (NextAuth Advisory).

Impact

If exploited, an attacker with access to logs could obtain sensitive information such as identity provider secrets. This information could then be used to impersonate the client and request extensive permissions from the identity provider (NextAuth Advisory).

Mitigation and workarounds

The vulnerability has been patched in versions 4.10.2 and 3.29.9 by moving the log for provider information to the debug level. Users should upgrade to these versions or later. Additionally, it is recommended to set debug: process.env.NODE_ENV !== 'production' to ensure debug logging is disabled in production environments. For those who need to log debug messages in production, it's recommended to use the logger option with proper sanitization of sensitive information (NextAuth Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66456CRITICAL9.1
  • JavaScriptJavaScript
  • elysia
NoYesDec 09, 2025
CVE-2025-66457HIGH7.5
  • JavaScriptJavaScript
  • elysia
NoYesDec 09, 2025
CVE-2025-65849MEDIUM6.9
  • JavaScriptJavaScript
  • altcha
NoNoDec 08, 2025
CVE-2025-66202MEDIUM6.5
  • JavaScriptJavaScript
  • astro
NoYesDec 09, 2025
CVE-2025-14284MEDIUM5.1
  • JavaScriptJavaScript
  • @tiptap/extension-link
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management