GHSA-26rv-h2hf-3fw4

Suggest an improvement
Source
https://github.com/advisories/GHSA-26rv-h2hf-3fw4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-26rv-h2hf-3fw4/GHSA-26rv-h2hf-3fw4.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-26rv-h2hf-3fw4
Aliases
  • CVE-2025-4644
Published
2025-08-29T12:31:11Z
Modified
2025-08-29T17:42:24.400218Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Payload's SQLite adapter Session Fixation vulnerability
Details

A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created user would receive the same identifier, allowing the attacker to reuse the JWT to authenticate and perform actions as that user.

This issue has been fixed in version 3.44.0 of Payload.

Database specific
{
    "nvd_published_at": "2025-08-29T10:15:32Z",
    "github_reviewed": true,
    "github_reviewed_at": "2025-08-29T16:59:05Z",
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-384"
    ]
}
References

Affected packages

npm / payload

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.44.0

npm / @payloadcms/next

Package

Name
@payloadcms/next
View open source insights on deps.dev
Purl
pkg:npm/%40payloadcms/next

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.44.0

npm / @payloadcms/graphql

Package

Name
@payloadcms/graphql
View open source insights on deps.dev
Purl
pkg:npm/%40payloadcms/graphql

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.44.0