Remote Code Execution Vulnerability in CISA Thorium Product
CVE-2025-35432

6.9MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-35432?

CISA Thorium has a vulnerability that allows attackers to exploit the system by sending an unlimited number of account verification email requests to users awaiting verification. This lack of rate limiting can lead to service disruption and potential abuse of the email verification process. The issue has been rectified in version 1.1.1 by introducing a default rate limit of 10 minutes, thereby mitigating the risk of such attacks.

Affected Version(s)

Thorium 1.0.0 < 1.1.1

Thorium 1.1.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

, OpenAI Security Research
.
CVE-2025-35432 : Remote Code Execution Vulnerability in CISA Thorium Product