PT-2025-35201 · Sqlite+1 · Sqlite+1

·

CVE-2025-4644

·

Published

2025-08-29

·

Updated

2025-09-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Payload versions prior to 3.44.0
Description A session fixation issue existed in Payload's SQLite adapter due to identifier reuse during account creation. An attacker could create an account, save its JSON Web Token (JWT), delete the account, and then reuse the JWT to authenticate as a subsequent user.
Recommendations Update to version 3.44.0 or later.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-4644
GHSA-26RV-H2HF-3FW4

Affected Products

Pyload
Sqlite