CVE-2025-32782

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 306

Summary

CVE-2025-32782 impacts the Ash Authentication system used for the Ash framework. This vulnerability arises from the confirmation flow during account creation, which relies on a GET request triggered by email links. Unintended account confirmations can occur when email clients or security tools automatically follow these links, enabling an attacker to register new accounts potentially with auto-confirmation by the victim's email client. This issue does not provide unauthorized access to existing accounts or private data and is resolved in version 4.7.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share