PT-2025-32422 · Workos · Authkit
Highmarji-Workos
·
Published
2025-08-08
·
Updated
2025-08-10
·
CVE-2025-55009
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
@workos-inc/authkit-remix versions 0.14.1 and below
Description
The AuthKit library for Remix exposed sensitive authentication artifacts – specifically
sealedSession and accessToken – by returning them from the authkitLoader, causing them to be rendered into the browser HTML. This could lead to session hijacking in environments where cross-site scripting (XSS), malicious browser extensions, or local inspection is possible.Recommendations
Update to version 0.15.0 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Authkit