CVE-2025-59453 LOW

CVE-2025-59453

Vendor Clickstudios
Product Passwordstate
Weakness CWE-669
Published September 16, 2025
Last update September 16, 2025

CVSS base score

3.2/10
Attack vector Local
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

What the vulnerability does

01Description

Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section.

Key dates

02Disclosure timeline

September 16, 2025 CVE published
September 16, 2025 Record updated