User Session Fixation after Account Removal in PayloadCMS
Published Aug 29, 2025
5.3
MEDIUMCVSS 4.0
EPSS 0.41%
Description
A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created user would receive the same identifier, allowing the attacker to reuse the JWT to authenticate and perform actions as that user.
This issue has been fixed in version 3.44.0 of Payload.
Affected products
-
- Version 0StatusaffectedConstraints<3.44.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Payload CMS | Payload | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
@payloadcms/graphql
npm
Introduced 0 Fixed 3.44.0payload
npm
Introduced 0 Fixed 3.44.0@payloadcms/next
npm
Introduced 0 Fixed 3.44.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @payloadcms/graphql | 0 | 3.44.0 |
| npm | payload | 0 | 3.44.0 |
| npm | @payloadcms/next | 0 | 3.44.0 |
Remediation
No remediation recorded yet.
References (7)
- https://cert.pl/en/posts/2025/08/CVE-2025-4643 third-party-advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26181 Advisory
- https://github.com/advisories/GHSA-26rv-h2hf-3fw4 Advisory
- https://github.com/payloadcms/payload product
- https://github.com/payloadcms/payload/commit/26d709dda6e512ce347557eaa2057db6e0cbf809
- https://nvd.nist.gov/vuln/detail/CVE-2025-4644
- https://payloadcms.com product
Change history (0)
No recorded changes yet.