Sensitive Authentication Artifacts Exposure in React Router Product by WorkOS
CVE-2025-55008
7.1HIGH
What is CVE-2025-55008?
The AuthKit library for React Router versions 0.6.1 and earlier contains a vulnerability where sensitive authentication artifacts, such as sealedSession and accessToken, are exposed through the authkitLoader. This flaw allows these sensitive elements to be rendered directly into the browser's HTML, which could lead to unauthorized access if exploited. The issue has been addressed in version 0.7.0, which implements necessary safeguards to prevent such leaks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
authkit-react-router < 0.7.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
