
Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)
Disclosure Date: 2025-06-11
Vendor fix date (per vendor): 2025-06-13
Researcher validation date: 2025-06-26
Discovered by: Sneden Rebello
A legacy user creation API pathway allowed accounts to be created without completing the intended email verification step. While unverified accounts could not access product features, this bypass still violated the designed verification and access-control flow and enabled creation of unintended accounts (e.g., spam/fake registrations).
Scope: limited to unauthenticated sign-up flows.
Data exposure: none observed; no access to existing user data or sessions.
MITRE Impact Classification: Denial of Service (resource exhaustion via unintended account creation)
Estimated severity: Medium (authentication/verification logic bypass; no direct data exposure)
CVSS v3.1 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS Base Score: 6.5 (Medium)
Vendor resolved the issue by:
These changes ensure that accounts can only be created after completing the intended email verification process.
Users of the platform do not need to take any action beyond ensuring they are on the current service version.
Note: Both the vendor’s internal fix date (2025-06-13) and the researcher validation date (2025-06-26) are recorded for transparency.
CVE-2025-65925 is publicly published on cve.org This advisory reflects the public disclosure associated with this CVE.
This follows coordinated vulnerability disclosure. Public details are intentionally high-level per vendor request; no internal identifiers, infrastructure details, or endpoint specifics are included. See DISCLOSURE_POLICY.md for more.
| Date & Time (UTC-04:00) | Event |
|---|
| 2025-06-11 12:09 | Vendor acknowledged receipt of report and began review |
| 2025-06-12 12:04 | Vendor confirmed high-severity portion will be addressed (low-severity items deprioritized) |
| 2025-06-13 | Vendor reports fix deployed for the user-creation verification issue |
| 2025-06-26 09:09 | Vendor notified researcher of deployment; researcher validated the fix |
| 2025-07-29 | Vendor confirmed additional redirect hardening (low-severity, non-CVE item); researcher re-tested successfully |
| 2025-12-18 | CVE ID assigned (CVE-2025-65925) |
| 2025-12-28 | Public advisory published by researcher |
| 2025-12-30 | CVE ID published (CVE-2025-65925) |