{"id":67729,"date":"2025-08-09T07:32:19","date_gmt":"2025-08-09T04:02:19","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-55008-workos-authkit-react-router-authentication-artifact-exposure\/"},"modified":"2025-08-09T07:32:19","modified_gmt":"2025-08-09T04:02:19","slug":"cve-2025-55008-workos-authkit-react-router-authentication-artifact-exposure","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-55008-workos-authkit-react-router-authentication-artifact-exposure\/","title":{"rendered":"CVE-2025-55008 &#8211; WorkOS AuthKit React Router Authentication Artifact Exposure"},"content":{"rendered":"<p><strong>CVE ID : <\/strong>CVE-2025-55008<br \/>\n<br \/>\n<strong>Published : <\/strong> Aug. 9, 2025, 3:15 a.m. | 16\u00a0minutes ago<br \/>\n<br \/>\n<strong>Description : <\/strong>The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS &amp; AuthKit with React Router. In versions 0.6.1 and below, @workos-inc\/authkit-react-router exposed sensitive authentication artifacts \u2014 specifically sealedSession and accessToken by returning them from the authkitLoader. This caused them to be rendered into the browser HTML. This issue is fixed in version 0.7.0.<br \/>\n<br \/>\n<strong>Severity:<\/strong> 7.1 | HIGH<br \/>\n<br \/>\nVisit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-55008 Published : Aug. 9, 2025, 3:15 a.m. | 16\u00a0minutes ago Description : The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS &amp; AuthKit with React Router. In versions 0.6.1 and below, @workos-inc\/authkit-react-router exposed sensitive authentication artifacts \u2014 specifically sealedSession and accessToken by returning them &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-67729","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/67729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=67729"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/67729\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=67729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=67729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=67729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}