CVE-2025-48371
OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users are affected under four specific conditions: First, calling Check API or ListObjects with an authorization model that has a relationship directly assignable by both type bound public access and userset; second, there are check or list object queries with contextual tuples for the relationship that can be directly assignable by both type bound public access and userset; third, those contextual tuples’s user field is an userset; and finally, type bound public access tuples are not assigned to the relationship. Users should upgrade to version 1.8.13 to receive a patch. The upgrade is backwards compatible.
EPSS 0.10% · 27.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | openfga/openfga | 1.8.0, 1.8.0 |
| openfga | helm_charts | 0.2.16, 0.2.16 |
| openfga | openfga | >= 1.8.0, < 1.8.13, 1.8.0, >= 1.8.0, < 1.8.13 |
Exploit Intelligence
Timeline
- May 22, 2025 CVE Published
- May 22, 2025 PoC Published
- May 23, 2025 EPSS Score
- Jun 3, 2025 EPSS Score
- Jun 14, 2025 EPSS Score
- Jun 25, 2025 EPSS Score
- Jul 6, 2025 EPSS Score
- Jul 18, 2025 EPSS Score
- Jul 29, 2025 EPSS Score
- Aug 9, 2025 EPSS Score
- Aug 20, 2025 EPSS Score
- Aug 31, 2025 EPSS Score
References
- https://github.com/openfga/openfga/security/advisories/GHSA-c72g-53hw-82q7 url
- https://github.com/openfga/openfga/commit/e5960d4eba92b723de8ff3a5346a07f50c1379ca url
- https://nvd.nist.gov/vuln/detail/CVE-2025-48371 advisory
- https://github.com/openfga/openfga package
- https://pkg.go.dev/vuln/GO-2025-3707 url