GHSA-v3gr-w9gf-23cx
The AuthKit Remix Library renders sensitive auth data in HTML
Quick fix
GHSA-v3gr-w9gf-23cx — @workos-inc/authkit-remix: upgrade to the fixed version with the command below.
npm install @workos-inc/authkit-remix@0.15.0Details
### Summary
Before `0.15.0`, `@workos-inc/authkit-remix` returned sensitive authentication artifacts from the `authkitLoader`, specifically `sealedSession` and `accessToken`. Because these values were returned from the loader, they were embedded into the server-rendered HTML and became readable by any script with access to the page’s DOM (e.g., in the presence of XSS or a malicious browser extension).
* **Impact:** Exposure of these secrets can lead to session hijacking and unauthorized API access. * **Fix:** Version `0.15.0` changes the default behavior so the loader no longer returns `sealedSession`/`accessToken`. A secure server-side mechanism is provided to fetch an access token when needed.
### Patches
Patched in [v0.15.0](https://github.com/workos/authkit-remix/releases/tag/v0.15.0).
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.15.0npm install @workos-inc/authkit-remix@0.15.0References
- https://github.com/workos/authkit-remix/security/advisories/GHSA-v3gr-w9gf-23cx[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-55009[ADVISORY]
- https://github.com/workos/authkit-remix/commit/20102afc74bf3dd5150a975a098067fb406b90b6[WEB]
- https://github.com/workos/authkit-remix[PACKAGE]
- https://github.com/workos/authkit-remix/releases/tag/v0.15.0[WEB]
- https://osv.dev/vulnerability/CVE-2025-55009[WEB]
- https://osv.dev/vulnerability/GHSA-v3gr-w9gf-23cx[WEB]