Vulnerabilities/

The AuthKit Remix Library renders sensitive auth data in HTML

Severity:
High

Description

Before 0.15.0, @workos-inc/authkit-remix returned sensitive authentication artifacts from the authkitLoader, specifically sealedSession and accessToken. Because these values were returned from the loader, they were embedded into the server-rendered HTML and became readable by any script with access to the page’s DOM (e.g.

Recommendation

Update the @workos-inc/authkit-remix package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@workos-inc/authkit-remix
Anything's wrong? Let us know Last updated on September 25, 2025

This issue is available in SmartScanner Professional

See Pricing