Description
Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is configured in the credentials.yml file. This could allow an attacker to submit voice data to the Rasa Pro assistant from an unauthenticated source. This issue has been patched for audiocodes, audiocodes_stream, and genesys connectors in versions 3.9.20, 3.10.19, 3.11.7 and 3.12.6.
Published: 2025-04-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11897 Rasa Pro Missing Authentication For Voice Connector APIs
Github GHSA Github GHSA GHSA-7xq5-54jp-2mfg Rasa Pro Missing Authentication For Voice Connector APIs
History

Fri, 18 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Description Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is configured in the credentials.yml file. This could allow an attacker to submit voice data to the Rasa Pro assistant from an unauthenticated source. This issue has been patched for audiocodes, audiocodes_stream, and genesys connectors in versions 3.9.20, 3.10.19, 3.11.7 and 3.12.6.
Title Rasa Pro Missing Authentication For Voice Connector APIs
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-18T20:35:41.744Z

Reserved: 2025-04-06T19:46:02.461Z

Link: CVE-2025-32377

cve-icon Vulnrichment

Updated: 2025-04-18T20:35:37.831Z

cve-icon NVD

Status : Deferred

Published: 2025-04-18T20:15:16.670

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-32377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses