Vulnerabilities/

The AuthKit React Router Library rendered sensitive auth data in HTML

Severity:
High

Description

In versions before 0.7.0, @workos-inc/authkit-react-router exposed sensitive authentication artifacts — specifically sealedSession and accessToken by returning them from the authkitLoader. This caused them to be rendered into the browser HTML.

Recommendation

Update the @workos-inc/authkit-react-router package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@workos-inc/authkit-react-router
Anything's wrong? Let us know Last updated on August 11, 2025

This issue is available in SmartScanner Professional

See Pricing