Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68113

23
FAUCET Score

CVE-2025-68113 describes a cryptographic semantic binding flaw in ALTCHA libraries, a privacy-first captcha and bot protection software. This vulnerability allows challenge payload splicing, potentially enabling replay attacks by reinterpreting valid proof-of-work submissions with modified expiration values. The CVSS score of 6.5 (Medium) indicates a network-based attack with low complexity, impacting the integrity and availability of abuse-prevention mechanisms, but not directly affecting data confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Users are advised to upgrade to patched versions of affected ALTCHA packages or implement the recommended mitigation of appending a delimiter to the salt value.

Impacted Technologies

VendorProductVersion(s)CPE
Altcha-OrgAltcha-Lib
< 1.4.1CNA affected

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 9th percentile among its peer group of 23,703 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

composerpatch availablevia ghsa
Product: altcha-org/altchaFixed in: 1.3.1
erlangpatch availablevia ghsa
Product: altchaFixed in: 1.0.0
gopatch availablevia ghsa
Product: github.com/altcha-org/altcha-lib-goFixed in: 1.0.0
mavenpatch availablevia ghsa
Product: org.altcha:altchaFixed in: 1.3.0
npmpatch availablevia ghsa
Product: altcha-libFixed in: 1.4.1
pippatch availablevia ghsa
Product: altchaFixed in: 1.0.0
rubygemspatch availablevia ghsa
Product: altchaFixed in: 1.0.0

Vendor Advisories (1)

npmGHSA-6gvq-jcmp-8959medium

ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay

Dec 16, 2025

References

github.com / altcha-org/altcha-lib/commit/cb95d83a8d08e273b6be15e48988e7eaf60d5c08
github.com / altcha-org/altcha-lib-ex/commit/09b2bad466ad0338a5b24245380950ea9918333e
github.com / altcha-org/altcha-lib-go/commit/4a5610745ef79895a67bac858b2e4f291c2614b8
github.com / altcha-org/altcha-lib-java/commit/69277651fdd6418ae10bf3a088901506f9c62114
github.com / altcha-org/altcha-lib-java/releases/tag/v1.3.0
github.com / altcha-org/altcha-lib-php/commit/9e9e70c864a9db960d071c77c778be0c9ff1a4d0
github.com / altcha-org/altcha-lib-php/releases/tag/v1.3.1
github.com / altcha-org/altcha-lib-rb/commit/4fd7b64cbbfc713f3ca4e066c2dd466e3b8d359b
github.com / altcha-org/altcha-lib/releases/tag/1.4.1
github.com / altcha-org/altcha-lib/security/advisories/GHSA-6gvq-jcmp-8959