PT-2025-32422 · Workos · Authkit

Highmarji-Workos

·

Published

2025-08-08

·

Updated

2025-08-10

·

CVE-2025-55009

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions @workos-inc/authkit-remix versions 0.14.1 and below
Description The AuthKit library for Remix exposed sensitive authentication artifacts – specifically sealedSession and accessToken – by returning them from the authkitLoader, causing them to be rendered into the browser HTML. This could lead to session hijacking in environments where cross-site scripting (XSS), malicious browser extensions, or local inspection is possible.
Recommendations Update to version 0.15.0 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-55009
GHSA-V3GR-W9GF-23CX

Affected Products

Authkit