Browse all 7 CVE security advisories affecting workos. AI-powered Chinese analysis, POCs, and references for each vulnerability.
WorkOS provides identity and access management solutions for enterprises, enabling secure authentication and authorization workflows. Historically, the platform has been susceptible to vulnerabilities including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation flaws, with seven CVEs documented to date. These issues often stem from improper input validation and misconfigured access controls. While no major public security incidents have been reported, the presence of multiple CVEs indicates potential risks in web application security and API protection. Organizations implementing WorkOS should ensure timely patching and conduct regular security assessments to mitigate these vulnerabilities.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-23017 | WorkOS Hosted AuthKit 安全漏洞 — Hosted AuthKitCWE-305 | 6.0 | Medium | 2025-02-24 |
This page lists every published CVE security advisory associated with workos. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.