{"id":"CVE-2025-32377","aliases":["PYSEC-2026-1862"],"url":"https://o3.security/vulnerability/CVE-2025-32377","summary":"Rasa Pro Missing Authentication For Voice Connector APIs","details":"## Vulnerability\nA vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is configured in the `credentials.yml` file. This could allow an attacker to submit voice data to the Rasa Pro assistant from an unauthenticated source.\n\nThis impacts the following connectors:\n\n- `audiocodes_stream`\n- `genesys`\n- `jambonz`\n\nAs part of our investigation to resolve this issue, we have also performed a security review of our other voice channel connectors:\n\n- `browser_audio`: Does not support authentication. This is a development channel not intended for production use.\n- `twilio_media_streams`, `twilio_voice` and `jambonz`: Authentication is currently not supported by these channels, but our investigation has found a way for us to enable it for these voice channel connectors in a future Rasa Pro release.\n\n## Fix\nThe issue has been resolved for `audiocodes`, `audiocodes_stream`, and `genesys` connectors. Fixed versions of Rasa Pro have been released for `3.9.20`, `3.10.19`, `3.11.7` and `3.12.6`. Please update to a fixed release.\n\nIf you are using one of the affected connectors, we strongly recommend upgrading to a fixed version. For connectors where authentication is not supported (e.g., Twilio), we suggest taking extra caution and considering other compensating controls if applicable.","published":"2025-04-17T18:33:20Z","modified":"2026-07-07T17:57:10.561101362Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"rasa-pro","fixedVersion":"3.12.6"},{"ecosystem":"PyPI","name":"rasa-pro","fixedVersion":"3.11.7"},{"ecosystem":"PyPI","name":"rasa-pro","fixedVersion":"3.10.19"},{"ecosystem":"PyPI","name":"rasa-pro","fixedVersion":"3.9.20"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/RasaHQ/rasa-pro-security-advisories/security/advisories/GHSA-7xq5-54jp-2mfg"},{"type":"WEB","url":"https://github.com/RasaHQ/security-advisories/security/advisories/GHSA-7xq5-54jp-2mfg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32377"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:57:10.561101362Z"}}