CVE-2025-4643

MEDIUM

Payload <3.44.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed). This issue has been fixed in version 3.44.0 of Payload.

Scores

CVSS v4 6.3
EPSS 0.0005
EPSS Percentile 16.1%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (4)
npm/payload 0 - 3.44.0npm
Payload CMS/Payload < 3.44.0
payloadcms/graphql 0 - 3.44.0npm
payloadcms/next 0 - 3.44.0npm
Published Aug 29, 2025
Tracked Since Feb 18, 2026