Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-32111

25
FAUCET Score

CVE-2025-32111 describes a high-severity vulnerability in Docker images built from acme.sh before commit 40b6db6, stemming from a missing "persist-credentials: false" setting in the .github/workflows/dockerhub.yml file. This configuration flaw, categorized as CWE-260, allows for a high-impact attack with a CVSS score of 8.7, indicating potential for significant compromise of confidentiality and integrity without user interaction. While the vulnerability is severe, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Acme.Sh ProjectAcme.Sh
>= 0, < 40b6db6a2715628aa977ed1853fe5256704010aeCNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

8.7HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 7th percentile among its peer group of 8,915 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / acmesh-official/acme.sh/commit/40b6db6a2715628aa977ed1853fe5256704010ae
github.com / acmesh-official/acme.sh/commit/a1de13657e79c5471dbc8fa3539ea39160937389
github.com / actions/checkout/blob/85e6279cec87321a52edac9c87bce653a07cf6c2/README.md