Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3gr-w9gf-23cx

Опубликовано: 08 авг. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

The AuthKit Remix Library renders sensitive auth data in HTML

Summary

Before 0.15.0, @workos-inc/authkit-remix returned sensitive authentication artifacts from the authkitLoader, specifically sealedSession and accessToken. Because these values were returned from the loader, they were embedded into the server-rendered HTML and became readable by any script with access to the page’s DOM (e.g., in the presence of XSS or a malicious browser extension).

  • Impact: Exposure of these secrets can lead to session hijacking and unauthorized API access.
  • Fix: Version 0.15.0 changes the default behavior so the loader no longer returns sealedSession/accessToken. A secure server-side mechanism is provided to fetch an access token when needed.

Patches

Patched in v0.15.0.

Пакеты

Наименование

@workos-inc/authkit-remix

npm
Затронутые версииВерсия исправления

< 0.15.0

0.15.0

EPSS

Процентиль: 20%
0.00063
Низкий

7.1 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.1
nvd
6 месяцев назад

The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In versions 0.14.1 and below, @workos-inc/authkit-remix exposed sensitive authentication artifacts — specifically sealedSession and accessToken — by returning them from the authkitLoader. This caused them to be rendered into the browser HTML.

EPSS

Процентиль: 20%
0.00063
Низкий

7.1 High

CVSS3

Дефекты

CWE-200