CVE Explorer
CVE-2025-68113
ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind challenge parameters to the nonce, allowing an attacker to reinterpret a valid proof-of-work submission with a modified expiration value. This may allow previously solved challenges to be reused beyond their intended lifetime, depending on server-side replay han
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-115","description":"CWE-115: Misinterpretation of Input","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"altcha-lib","vendor":"altcha-org","versions":[{"status":"affected","version":"< 1.4.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-115","description":"CWE-115: Misinterpretation of Input","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/problemTypes/0/descriptions/0
Source references
10 source assertions{"name":"https://github.com/altcha-org/altcha-lib-ex/commit/09b2bad466ad0338a5b24245380950ea9918333e","tags":["x_refsource_MISC"],"url":"https://github.com/altcha-org/altcha-lib-ex/commit/09b2bad466ad0338a5b24245380950ea9918333e"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/1
{"name":"https://github.com/altcha-org/altcha-lib-go/commit/4a5610745ef79895a67bac858b2e4f291c2614b8","tags":["x_refsource_MISC"],"url":"https://github.com/altcha-org/altcha-lib-go/commit/4a5610745ef79895a67bac858b2e4f291c2614b8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/2
{"name":"https://github.com/altcha-org/altcha-lib-java/commit/69277651fdd6418ae10bf3a088901506f9c62114","tags":["x_refsource_MISC"],"url":"https://github.com/altcha-org/altcha-lib-java/commit/69277651fdd6418ae10bf3a088901506f9c62114"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/3
{"name":"https://github.com/altcha-org/altcha-lib-java/releases/tag/v1.3.0","tags":["x_refsource_MISC"],"url":"https://github.com/altcha-org/altcha-lib-java/releases/tag/v1.3.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/7
{"name":"https://github.com/altcha-org/altcha-lib-php/commit/9e9e70c864a9db960d071c77c778be0c9ff1a4d0","tags":["x_refsource_MISC"],"url":"https://github.com/altcha-org/altcha-lib-php/commit/9e9e70c864a9db960d071c77c778be0c9ff1a4d0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/4
{"name":"https://github.com/altcha-org/altcha-lib-php/releases/tag/v1.3.1","tags":["x_refsource_MISC"],"url":"https://github.com/altcha-org/altcha-lib-php/releases/tag/v1.3.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/8
{"name":"https://github.com/altcha-org/altcha-lib-rb/commit/4fd7b64cbbfc713f3ca4e066c2dd466e3b8d359b","tags":["x_refsource_MISC"],"url":"https://github.com/altcha-org/altcha-lib-rb/commit/4fd7b64cbbfc713f3ca4e066c2dd466e3b8d359b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/5
{"name":"https://github.com/altcha-org/altcha-lib/commit/cb95d83a8d08e273b6be15e48988e7eaf60d5c08","tags":["x_refsource_MISC"],"url":"https://github.com/altcha-org/altcha-lib/commit/cb95d83a8d08e273b6be15e48988e7eaf60d5c08"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/6
{"name":"https://github.com/altcha-org/altcha-lib/releases/tag/1.4.1","tags":["x_refsource_MISC"],"url":"https://github.com/altcha-org/altcha-lib/releases/tag/1.4.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/9
{"name":"https://github.com/altcha-org/altcha-lib/security/advisories/GHSA-6gvq-jcmp-8959","tags":["x_refsource_CONFIRM"],"url":"https://github.com/altcha-org/altcha-lib/security/advisories/GHSA-6gvq-jcmp-8959"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:509594575178d49f544c4c3d70a91aa50d1099da72fb93799fe9fd7bd8d49be0 · sha256:2d3cb744a5254fbb… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.