PT-2025-36939 · Saleor · Saleor

Nyankiyoshi

·

Published

2025-09-09

·

Updated

2025-09-09

·

CVE-2025-58442

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Saleor versions 3.21.0 through 3.21.15
Description: Saleor is an e-commerce platform. Requesting certain fields in the response of the accountRegister API endpoint may reveal whether a user with a provided email address already exists in the system. This could potentially expose user account information. As a workaround, rate-limiting the mutation is recommended to reduce the impact.
Recommendations: Update to version 3.21.16 or later. Rate-limit the accountRegister mutation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-58442
GHSA-8W67-MFM5-FWX5

Affected Products

Saleor