Intel

AIKIDO-2025-10942

altcha-org/altcha is vulnerable to Improper Neutralization of Parameter/Argument Delimiters

Improper Neutralization of Parameter/Argument DelimitersGHSA-6gvq-jcmp-8959 Published Dec 15, 2025

56

Medium Risk

This Affects:

PHPaltcha-org/altcha
0.1.0 - 1.3.0
Fixed in 1.3.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a parameter splicing vulnerability in the salt handling logic where the application failed to consistently enforce a delimiter, allowing an attacker to exploit this by injecting a custom delimiter into the salt parameter to maliciously splice and control the resulting composite string, thereby enabling authentication bypass or replay attacks where a previously observed hashed value could be fraudulently reused.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

altcha-org/altcha is vulnerable to Improper Neutralization of Parameter/Argument Delimiters in versions 0.1.0 - 1.3.0.

How to fix this

Upgrade the altcha-org/altcha library to the patch version.