CVE-2025-32782
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 306
Summary
CVE-2025-32782 impacts the Ash Authentication system used for the Ash framework. This vulnerability arises from the confirmation flow during account creation, which relies on a GET request triggered by email links. Unintended account confirmations can occur when email clients or security tools automatically follow these links, enabling an attacker to register new accounts potentially with auto-confirmation by the victim's email client. This issue does not provide unauthorized access to existing accounts or private data and is resolved in version 4.7.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.