Intel

AIKIDO-2025-10124

captcha is vulnerable to Use of Insufficiently Random Values

Use of Insufficiently Random Values Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 3, 2025

42

Medium Risk

This Affects:

PYTHONcaptcha
0.1 - 0.7.0
Fixed in 0.7.1
Are you affected? Scan for Free

TL;DR

Affected versions of the captcha library may be vulnerable due to the use of insufficiently random values when adding noise to audio and image captchas. If these values are predictable or lack proper randomness, attackers could exploit this weakness to generate captchas that are easier to solve, potentially bypassing security mechanisms.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

captcha is vulnerable to Use of Insufficiently Random Values in versions 0.1 - 0.7.0.

How to fix this

Upgrade the captcha library to the patch version.