GHSA-vqvc-9q8x-vmq6
HIGHCVE-2025-55008In versions before 0.7.0, @workos-inc/authkit-react-router exposed sensitive authentication artifacts — specifically sealedSession and accessToken by returning them from the authkitLoader. This caused them to be rendered into the browser HTML.
- Affected
- < 0.7.0
- Fixed in
- 0.7.0
- Weakness
- CWE-200
- Published
- 2025-08-08
- Source
- github