Vulnerability Description
The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In versions 0.14.1 and below, @workos-inc/authkit-remix exposed sensitive authentication artifacts — specifically sealedSession and accessToken — by returning them from the authkitLoader. This caused them to be rendered into the browser HTML.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/workos/authkit-remix/commit/20102afc74bf3dd5150a975a098067fb4
- https://github.com/workos/authkit-remix/releases/tag/v0.15.0
- https://github.com/workos/authkit-remix/security/advisories/GHSA-v3gr-w9gf-23cx
FAQ
What is CVE-2025-55009?
CVE-2025-55009 is a vulnerability with a CVSS score of 7.1 (HIGH). The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In versions 0.14.1 and below, @workos-inc/authkit-remix exposed s...
How severe is CVE-2025-55009?
CVE-2025-55009 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55009?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.