CVE-2025-32111: Acme.sh Project Acme.sh
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.
Affected products
- Acme.sh Project Acme.sh
Published 2025-04-04. Last modified 2026-06-17.