CVE-2025-23017: Workos Hosted Authkit

Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.

WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred.

Affected products

  • Workos Hosted Authkit: before 2025-01-07 (fixed in 2025-01-07)

Published 2025-02-24. Last modified 2026-06-17.