Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-32782

17
FAUCET Score

CVE-2025-32782 affects Ash Authentication, a component of the Ash framework, where the account creation confirmation flow uses a GET request. Certain email clients or security tools may automatically follow the confirmation link, leading to unintended account confirmation. This allows an attacker to register a new account using a victim's email, which could then be auto-confirmed without the victim's explicit action. Rated Medium (CVSS 5.3), this vulnerability has a low impact, as it only affects new account confirmation and does not allow access to existing accounts or private data. The attack vector is network-based with low complexity, requiring no user interaction. Currently, there is no evidence of active exploitation, nor are there any public exploit codes available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage are minimal, indicating low public awareness.

Impacted Technologies

VendorProductVersion(s)CPE
Team-AlembicAsh Authentication
< 4.7.0CNA affected

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 12th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

erlangpatch availablevia ghsa
Product: ash_authenticationFixed in: 4.7.0

Vendor Advisories (1)

erlangGHSA-3988-q8q7-p787medium

ash_authentication has email link auto-click account confirmation vulnerability

Apr 14, 2025

References

github.com / team-alembic/ash_authentication/commit/99ea38977fd4f421d2aaae0c2fb29f8e5f8f707d
github.com / team-alembic/ash_authentication/security/advisories/GHSA-3988-q8q7-p787