PT-2025-47578 · Unknown · Couch-Auth

CVE-2025-60794

·

Published

2025-11-20

·

Updated

2025-12-12

CVSS v4.0

6.6

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions couch-auth version 0.21.2
Description Session tokens and passwords are stored in JavaScript objects within the software and are not explicitly cleared from memory. This occurs in src/user.ts lines 700-707, creating a potential for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, which could lead to session hijacking.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the user.ts file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60794
GHSA-62VX-HPCR-M9CH

Affected Products

Couch-Auth