CVE-2025-55009 describes a vulnerability in @workos-inc/authkit-remix versions 0.14.1 and below, where sensitive authentication artifacts like sealedSession and accessToken were inadvertently exposed in the browser's HTML due to being returned by the authkitLoader. This high-severity flaw (CVSS 7.1) has a network attack vector and high impact on confidentiality and integrity, though it requires low privileges and high attack complexity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Workos | Authkit-Remix | < 0.15.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.