github.com
https://github.com/perfood/couch-auth CVE-2025-60794
@perfood/couch-auth may expose session tokens, passwords
Description
Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially leading to session hijacking.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
@perfood/couch-authBrowse npm / @perfood/couch-auth | GitHub Advisory | Through 0.21.2 | affected |
References
4github.com
https://github.com/pr0wl1ng/security-advisories/blob/main/CVE-2025-60794.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-60794 npmjs.com
https://www.npmjs.com/package/@perfood/couch-auth