Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Highmarji-Workos

Researcher fromWorkOS
#39125of 53,632
7.1Total CVSS
Vulnerabilities · 1
PT-2025-32422
7.1
2025-08-08
Workos · Authkit · CVE-2025-55009
**Name of the Vulnerable Software and Affected Versions** @workos-inc/authkit-remix versions 0.14.1 and below **Description** The AuthKit library for Remix exposed sensitive authentication artifacts – specifically `sealedSession` and `accessToken` – by returning them from the `authkitLoader`, causing them to be rendered into the browser HTML. This could lead to session hijacking in environments where cross-site scripting (XSS), malicious browser extensions, or local inspection is possible. **Recommendations** Update to version 0.15.0 or later.