CVE-2025-4644

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
29/08/2025
Last modified:
29/08/2025

Description

A Session Fixation vulnerability existed in Payload&amp;#39;s SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created user would receive the same identifier, allowing the attacker to reuse the JWT to authenticate and perform actions as that user.<br /> <br /> This issue has been fixed in version 3.44.0 of Payload.