Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2025-32782 — ash-authentication

🟡 CVSS 5.3 — Medium ✅ No Known Exploit CWE-306 NVD
5.3
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

ash_authentication has email link auto-click account confirmation vulnerability

Impact

The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security tools (e.g., Outlook, virus scanners, and email previewers) may automatically follow these links, unintentionally confirming the account. This allows an attacker to register an account using another user’s email and potentially have it auto-confirmed by the victim’s email client.

This does not allow attackers to take over or access existing accounts or private data. It is limited to account confirmation of new accounts only.

Patches

A mitigation has been released in version 4.7.0. You will also need to upgrade to 2.6.0 or later of ash_authentication_phoenix to take advantage of the autogenerated views for confirmation. The fix updates the confirmation flow to require explicit user interaction (such as clicking a button on the confirmation page) rather than performing the confirmation via a GET request. This ensures that automatic link prefetching or scanning by email clients does not unintentionally confirm accounts.

To mitigate, follow these steps:

1. Upgrade ash_authentication >= 4.7.0

2. Upgrade ash_authentication_phoenix >= 2.6.0 (if using ash_authentication_phoenix)

3. Set require_interaction? true in your confirmation strategy.

4. Add confirm_route to your router, if using ash_authentication_phoenix *above* auth_routes.

Setting require_interaction? true

modify your confirmation strategy like so:

```elixir

confirmation <strategy_name> do

...

require_interaction? true

end

```

Adding the confirm_route to your router

In order to use this new confirmation flow, you will need to add this to your router to get the desired behavior. It will add a new route to the new confirmation page LiveView. Note the path and token_as_route_param? options, required for keeping backwards compatibility with current defaults. You may need to adjust if you have changed those routes in some way.

IMPORTANT - above auth_routes

Make sure this goes *above* auth_routes if you are using the path option, and it begins with /auth,

or whatever your configured auth_routes_prefix is. auth_routes greedily handles all routes at the

configured path.

```elixir

confirm_route(

MyApp.Accounts.User,

<confirmation_strategy_name>,

auth_routes_prefix: "/auth",

overrides: [MyAppWeb.AuthOverrides, AshAuthentication.Phoenix.Overrides.Default],

# use these options to keep your currently issued confirmation emails compatible

# without the options below, the route will default to /<the_strategy_name>/:token

path: "/auth/user/<confirmation_strategy_name>",

token_as_route_param?: false

)

```

Users should upgrade to version 4.7.0 as soon as possible, and set require_interaction? to true in their confirmation strategy. This will change the GET request generated for confirming to a POST request.

If you upgrade to this version and do not set require_interaction? to true, compilation will be fail with a message linking to this advisory. This error can be bypassed if, for example, you are confident that you are not affected.

Workarounds

_Is there a way for users to fix or remediate the vulnerability without upgrading?_

You can disable the confirmation routes and create your own live view. We highly advised that you upgrade and take advantage of the builtin views if possible. If you are not using the provided views, you will need to *add* a confirmation LiveView, that does a POST to the old confirmation url instead of a GET. You would do this by taking the token a parameter out of the link, and adding it as a hidden field to a form. That form would have no inputs, only a button that posts to the confirmation URL. If you are using Liveview, this would be done with phx-trigger-action and phx-action.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity low, availability none.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Privileges required: None — an unauthenticated stranger can try it.
  • User interaction: None — nobody has to be tricked into anything.
  • Scope: Unchanged — the damage stays inside the vulnerable component.
  • Confidentiality impact: None.
  • Integrity impact: Low — limited, and the attacker does not choose what is affected.
  • Availability impact: None.

Weakness class

CVE-2025-32782 is classified as CWE-306: Missing Authentication for Critical Function. A sensitive function can be reached without authenticating at all.

Affected software

CVE-2025-32782 is recorded against 2 packages.

  • ash-authentication
  • unknown

Timeline and source

Published on 14 April 2025 and last revised on 10 December 2025. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)

Other advisories for this package

ash-authentication has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-306: Missing Authentication for Critical Function) in other software:

Details

Severity Medium
CVSS Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE CWE-306
Public Exploit ✅ No
Source NVD
Published 2025-04-14
Updated 2026-08-20
Modified 2025-12-10
Fix URL N/A

Affected Packages

Software From version Fixed in
ash-authentication
unknown

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in ash-authentication

CVE-2025-32782 is rated CVSS 5.3 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2025