Executive brief
The AuthKit React Router library is used to manage authentication in React applications. Before version 0.7.0, the library exposed sensitive authentication credentials (session tokens and access tokens) directly in the HTML sent to browsers, making them visible to attackers exploiting XSS vulnerabilities, installing malicious browser extensions, or with local machine access. This could allow attackers to hijack user sessions.
Technical details
The vulnerability is an information disclosure (CWE-200) in the authkitLoader function, which returned sensitive authentication artifacts (sealedSession and accessToken) that were subsequently rendered into the browser's HTML. The vulnerability requires network access plus low-level privileges and high attack complexity (XSS exploitation, malicious extensions, or local access). An attacker exploiting this can obtain authentication tokens to hijack sessions and potentially modify user data. The vulnerability was patched in version 0.7.0, which removed these secrets from the default authkitLoader return and provides a secure server-side token fetching mechanism instead.
Affected products
- WorkOS AuthKit React Router before 0.7.0
Timeline
- 2025-08-08: disclosed
- 2025-08-08: patched: Version 0.7.0 released