# CVE-2025-32111

## Summary

- **CVE ID:** CVE-2025-32111
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N)
- **CWE:** CWE-260
- **Published:** Apr 4, 2025
- **Last Modified:** Mar 13, 2026

## Description

The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.

## Affected Products

- acme.sh project — acme.sh (0)

## References

- [CNA](https://github.com/acmesh-official/acme.sh/commit/a1de13657e79c5471dbc8fa3539ea39160937389)
- [CNA](https://github.com/acmesh-official/acme.sh/commit/40b6db6a2715628aa977ed1853fe5256704010ae)
- [CNA](https://github.com/actions/checkout/blob/85e6279cec87321a52edac9c87bce653a07cf6c2/README.md?plain=1#L70-L72)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._