Vulnerability Description
Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in errors that could unintentionally reveal whether a user with the provided email already exists in Saleor. Version 3.21.16 fixes the issue. As a workaround, rate-limit the mutation to reduce the impact.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/saleor/saleor/commit/09d671e91ea53a44352d5f685083dc05a2f55e95
- https://github.com/saleor/saleor/commit/b35783838e51cfc118e07d632f64b01bc3a2c4bb
- https://github.com/saleor/saleor/releases/tag/3.21.16
- https://github.com/saleor/saleor/security/advisories/GHSA-8w67-mfm5-fwx5
FAQ
What is CVE-2025-58442?
CVE-2025-58442 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in errors that could unintentionall...
How severe is CVE-2025-58442?
CVE-2025-58442 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-58442?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.