PT-2025-32422 · Workos · Authkit

·

CVE-2025-55009

·

Published

2025-08-08

·

Updated

2025-08-10

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions @workos-inc/authkit-remix versions 0.14.1 and below
Description The AuthKit library for Remix exposed sensitive authentication artifacts – specifically sealedSession and accessToken – by returning them from the authkitLoader, causing them to be rendered into the browser HTML. This could lead to session hijacking in environments where cross-site scripting (XSS), malicious browser extensions, or local inspection is possible.
Recommendations Update to version 0.15.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55009
GHSA-V3GR-W9GF-23CX

Affected Products

Authkit