Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24030 | The AuthKit Remix Library renders sensitive auth data in HTML |
Github GHSA |
GHSA-v3gr-w9gf-23cx | The AuthKit Remix Library renders sensitive auth data in HTML |
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Workos
Workos authkit |
|
| Vendors & Products |
Workos
Workos authkit |
Mon, 11 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 09 Aug 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In versions 0.14.1 and below, @workos-inc/authkit-remix exposed sensitive authentication artifacts — specifically sealedSession and accessToken — by returning them from the authkitLoader. This caused them to be rendered into the browser HTML. | |
| Title | AuthKit: Sensitive auth data rendered in HTML | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-11T14:35:52.345Z
Reserved: 2025-08-04T17:34:24.422Z
Link: CVE-2025-55009
Updated: 2025-08-11T14:35:45.609Z
Status : Deferred
Published: 2025-08-09T03:15:47.483
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-55009
No data.
OpenCVE Enrichment
Updated: 2025-08-12T11:47:08Z
EUVD
Github GHSA