Memory Vulnerability in Couch-Auth by Perfood
CVE-2025-60794
What is CVE-2025-60794?
A vulnerability in Couch-Auth version 0.21.2 allows session tokens and passwords to be stored in JavaScript objects that remain in memory without proper removal. This oversight poses a risk as these sensitive credentials may be accessible through memory analyses, utilizing tools such as memory dumps or debugging techniques. As a result, attackers can exploit this vulnerability to gain unauthorized access to user sessions, thereby compromising security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
News Articles
CVE-2025-60794 Impact, Exploitability, and Mitigation Steps | Wiz
Understand the critical aspects of CVE-2025-60794 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
References
CVSS V3.1
Timeline
- ๐ฐ
First article discovered by wiz.io
Vulnerability published
Vulnerability Reserved
