{"id":"GHSA-v3gr-w9gf-23cx","summary":"The AuthKit Remix Library renders sensitive auth data in HTML","details":"### Summary\n\nBefore `0.15.0`, `@workos-inc/authkit-remix` returned sensitive authentication artifacts from the `authkitLoader`, specifically `sealedSession` and `accessToken`. Because these values were returned from the loader, they were embedded into the server-rendered HTML and became readable by any script with access to the page’s DOM (e.g., in the presence of XSS or a malicious browser extension).\n\n*   **Impact:** Exposure of these secrets can lead to session hijacking and unauthorized API access.\n*   **Fix:** Version `0.15.0` changes the default behavior so the loader no longer returns `sealedSession`/`accessToken`. A secure server-side mechanism is provided to fetch an access token when needed.\n\n### Patches\n\nPatched in [v0.15.0](https://github.com/workos/authkit-remix/releases/tag/v0.15.0).","aliases":["CVE-2025-55009"],"modified":"2025-09-25T22:56:19Z","published":"2025-08-08T17:08:46Z","database_specific":{"nvd_published_at":"2025-08-09T03:15:47Z","cwe_ids":["CWE-200"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-08-08T17:08:46Z"},"references":[{"type":"WEB","url":"https://github.com/workos/authkit-remix/security/advisories/GHSA-v3gr-w9gf-23cx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55009"},{"type":"WEB","url":"https://github.com/workos/authkit-remix/commit/20102afc74bf3dd5150a975a098067fb406b90b6"},{"type":"PACKAGE","url":"https://github.com/workos/authkit-remix"},{"type":"WEB","url":"https://github.com/workos/authkit-remix/releases/tag/v0.15.0"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2025-55009"},{"type":"WEB","url":"https://osv.dev/vulnerability/GHSA-v3gr-w9gf-23cx"}],"affected":[{"package":{"name":"@workos-inc/authkit-remix","ecosystem":"npm","purl":"pkg:npm/%40workos-inc/authkit-remix"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.15.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-v3gr-w9gf-23cx/GHSA-v3gr-w9gf-23cx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L"}]}