CVE-2025-60794 is a medium-severity vulnerability affecting perfood couchauth versions 0.21.2 and earlier. It involves the insecure storage of session tokens and passwords in memory, specifically within JavaScript objects, without proper clearing. This flaw, rated 6.5 CVSS, allows an attacker with memory access to potentially extract sensitive data, leading to session hijacking. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.21.2CPE matchmatch criteria | cpe:2.3:a:perfood:couchauth:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.