CVE-2025-59453

LOW

Click Studios Passwordstate <9.9.9972 - Auth Bypass

Title source: llm
STIX 2.1

Description

Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section.

Scores

CVSS v3 3.2
EPSS 0.0002
EPSS Percentile 4.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-669
Status published
Products (1)
clickstudios/Passwordstate < 9.9 Build 9972
Published Sep 16, 2025
Tracked Since Feb 18, 2026