Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24029 | The AuthKit React Router Library rendered sensitive auth data in HTML |
Github GHSA |
GHSA-vqvc-9q8x-vmq6 | The AuthKit React Router Library rendered sensitive auth data in HTML |
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Workos
Workos authkit |
|
| Vendors & Products |
Workos
Workos authkit |
Mon, 11 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 09 Aug 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In versions 0.6.1 and below, @workos-inc/authkit-react-router exposed sensitive authentication artifacts — specifically sealedSession and accessToken by returning them from the authkitLoader. This caused them to be rendered into the browser HTML. This issue is fixed in version 0.7.0. | |
| Title | AuthKit React Router: Sensitive auth data rendered in HTML | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-11T14:33:33.678Z
Reserved: 2025-08-04T17:34:24.422Z
Link: CVE-2025-55008
Updated: 2025-08-11T14:33:25.226Z
Status : Deferred
Published: 2025-08-09T03:15:47.327
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-55008
No data.
OpenCVE Enrichment
Updated: 2025-08-12T11:47:15Z
EUVD
Github GHSA