CVE-2025-32782 affects Ash Authentication, a component of the Ash framework, where the account creation confirmation flow uses a GET request. Certain email clients or security tools may automatically follow the confirmation link, leading to unintended account confirmation. This allows an attacker to register a new account using a victim's email, which could then be auto-confirmed without the victim's explicit action. Rated Medium (CVSS 5.3), this vulnerability has a low impact, as it only affects new account confirmation and does not allow access to existing accounts or private data. The attack vector is network-based with low complexity, requiring no user interaction. Currently, there is no evidence of active exploitation, nor are there any public exploit codes available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Team-Alembic | Ash Authentication | < 4.7.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.