Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

workos — Vulnerabilities & Security Advisories 8

Browse all 8 CVE security advisories affecting workos. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WorkOS provides identity and access management solutions for enterprises, enabling secure authentication and authorization workflows. Historically, the platform has been susceptible to vulnerabilities including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation flaws, with seven CVEs documented to date. These issues often stem from improper input validation and misconfigured access controls. While no major public security incidents have been reported, the presence of multiple CVEs indicates potential risks in web application security and API protection. Organizations implementing WorkOS should ensure timely patching and conduct regular security assessments to mitigate these vulnerabilities.

Found 2 results / 8 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-55009 AuthKit: Sensitive auth data rendered in HTML — authkit-remix CWE-200 7.1 High 2025-08-09
CVE-2024-51753 Refresh tokens are logged when the debug flag is enabled in @workos-inc/authkit-remix — authkit-remix CWE-532 5.3AI Medium AI 2024-11-05

This page lists every published CVE security advisory associated with workos. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.