VDB
Sign up
HIGH7.1

GHSA-v3gr-w9gf-23cx

The AuthKit Remix Library renders sensitive auth data in HTML

Quick fix

GHSA-v3gr-w9gf-23cx — @workos-inc/authkit-remix: upgrade to the fixed version with the command below.

npm install @workos-inc/authkit-remix@0.15.0

Details

### Summary

Before `0.15.0`, `@workos-inc/authkit-remix` returned sensitive authentication artifacts from the `authkitLoader`, specifically `sealedSession` and `accessToken`. Because these values were returned from the loader, they were embedded into the server-rendered HTML and became readable by any script with access to the page’s DOM (e.g., in the presence of XSS or a malicious browser extension).

* **Impact:** Exposure of these secrets can lead to session hijacking and unauthorized API access. * **Fix:** Version `0.15.0` changes the default behavior so the loader no longer returns `sealedSession`/`accessToken`. A secure server-side mechanism is provided to fetch an access token when needed.

### Patches

Patched in [v0.15.0](https://github.com/workos/authkit-remix/releases/tag/v0.15.0).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@workos-inc/authkit-remix
Introduced in: 0Fixed in: 0.15.0
Fixnpm install @workos-inc/authkit-remix@0.15.0

References