{"id":"CVE-2025-32377","aliases":["GHSA-7xq5-54jp-2mfg","PYSEC-2026-1862"],"title":"Rasa Pro Missing Authentication For Voice Connector APIs","summary":"Rasa Pro Missing Authentication For Voice Connector APIs","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","vendor":"rasa-pro","product":"rasa-pro","ecosystem":"pip","affected":["rasa-pro >= 3.12.0, < 3.12.6","rasa-pro >= 3.11.0, < 3.11.7","rasa-pro >= 3.10.0, < 3.10.19","rasa-pro < 3.9.20"],"patched":["rasa-pro 3.12.6","rasa-pro 3.11.7","rasa-pro 3.10.19","rasa-pro 3.9.20"],"published":"2025-04-17","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7xq5-54jp-2mfg","references":[{"url":"https://github.com/RasaHQ/rasa-pro-security-advisories/security/advisories/GHSA-7xq5-54jp-2mfg"},{"url":"https://github.com/RasaHQ/security-advisories/security/advisories/GHSA-7xq5-54jp-2mfg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32377"}],"tags":["osv","pip"],"epss":0.00464,"epssPercentile":0.39432,"ingestedAt":"2026-07-08T18:25:47.257Z","slug":"CVE-2025-32377","body":"## Overview\n\n## Vulnerability\nA vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is configured in the `credentials.yml` file. This could allow an attacker to submit voice data to the Rasa Pro assistant from an unauthenticated source.\n\nThis impacts the following connectors:\n\n- `audiocodes_stream`\n- `genesys`\n- `jambonz`\n\nAs part of our investigation to resolve this issue, we have also performed a security review of our other voice channel connectors:\n\n- `browser_audio`: Does not support authentication. This is a development channel not intended for production use.\n- `twilio_media_streams`, `twilio_voice` and `jambonz`: Authentication is currently not supported by these channels, but our investigation has found a way for us to enable it for these voice channel connectors in a future Rasa Pro release.\n\n## Fix\nThe issue has been resolved for `audiocodes`, `audiocodes_stream`, and `genesys` connectors. Fixed versions of Rasa Pro have been released for `3.9.20`, `3.10.19`, `3.11.7` and `3.12.6`. Please update to a fixed release.\n\nIf you are using one of the affected connectors, we strongly recommend upgrading to a fixed version. For connectors where authentication is not supported (e.g., Twilio), we suggest taking extra caution and considering other compensating controls if applicable.\n\n## Affected packages\n\n- `rasa-pro >= 3.12.0, < 3.12.6`\n- `rasa-pro >= 3.11.0, < 3.11.7`\n- `rasa-pro >= 3.10.0, < 3.10.19`\n- `rasa-pro < 3.9.20`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `rasa-pro 3.12.6`\n- `rasa-pro 3.11.7`\n- `rasa-pro 3.10.19`\n- `rasa-pro 3.9.20`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}