CVE-2025-68113
unknown
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
โ
Description
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Predictions
Exploit likelihood
30%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| RubyGems | altcha | <>= 1.0.0 | >= 1.0.0 |
| npm | altcha-lib | <1.4.1 | 1.4.1 |
| Packagist | altcha-org/altcha | <1.3.1 | 1.3.1 |
| Go | github.com/altcha-org/altcha-lib-go | <1.0.0 | 1.0.0 |
| Maven | org.altcha:altcha | <1.3.0 | 1.3.0 |
| RubyGems | altcha | <1.0.0 | 1.0.0 |
| PyPI | altcha | <1.0.0 | 1.0.0 |
| Hex | altcha | <1.0.0 | 1.0.0 |
References
- https://github.com/altcha-org/altcha-lib/security/advisories/GHSA-6gvq-jcmp-8959
- https://nvd.nist.gov/vuln/detail/CVE-2025-68113
- https://github.com/altcha-org/altcha-lib-ex/commit/09b2bad466ad0338a5b24245380950ea9918333e
- https://github.com/altcha-org/altcha-lib-go/commit/4a5610745ef79895a67bac858b2e4f291c2614b8
- https://github.com/altcha-org/altcha-lib-java/commit/69277651fdd6418ae10bf3a088901506f9c62114
- https://github.com/altcha-org/altcha-lib-php/commit/9e9e70c864a9db960d071c77c778be0c9ff1a4d0
- https://github.com/altcha-org/altcha-lib-rb/commit/4fd7b64cbbfc713f3ca4e066c2dd466e3b8d359b
- https://github.com/altcha-org/altcha-lib/commit/cb95d83a8d08e273b6be15e48988e7eaf60d5c08
- https://github.com/altcha-org/altcha-lib
- https://github.com/altcha-org/altcha-lib-java/releases/tag/v1.3.0
- https://github.com/altcha-org/altcha-lib-php/releases/tag/v1.3.1
- https://github.com/altcha-org/altcha-lib/releases/tag/1.4.1
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/altcha/CVE-2025-68113.yml
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.