CVE-2025-4644: User Session Fixation after Account Removal in PayloadCMS
A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created user would receive the same identifier, allowing the attacker to reuse the JWT to authenticate and perform actions as that user.
This issue has been fixed in version 3.44.0 of Payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4644?
CVE-2025-4644 is considered a high severity vulnerability due to its potential for session fixation attacks.
How does CVE-2025-4644 affect account security?
CVE-2025-4644 allows attackers to reuse a valid JSON Web Token (JWT) after an account is deleted, compromising account security.
Is my version of Payload affected by CVE-2025-4644?
Yes, versions of Payload up to 3.44.0 are affected by CVE-2025-4644.
How do I fix CVE-2025-4644?
To fix CVE-2025-4644, update Payload to a version later than 3.44.0 where the vulnerability has been addressed.
What are the consequences of ignoring CVE-2025-4644?
Ignoring CVE-2025-4644 could allow unauthorized access to user accounts due to the exploitation of handled JWTs.