CVE-2025-4644
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
29/08/2025
Last modified:
29/08/2025
Description
A Session Fixation vulnerability existed in Payload&#39;s SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created user would receive the same identifier, allowing the attacker to reuse the JWT to authenticate and perform actions as that user.<br />
<br />
This issue has been fixed in version 3.44.0 of Payload.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM



