CVE-2025-25196

Updated on 19 Feb 2025

Severity

5.8 Medium severity

Details

CVSS score
5.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

Overview OpenFGA v1.8.4 or previous (Helm chart < openfga-0.2.22, docker < v.1.8.5) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.

Am I Affected? If you are using OpenFGA v1.8.4 or previous, specifically under the following conditions, you are affected by this authorization bypass vulnerability:

Fix Upgrade to v1.8.5. This upgrade is backwards compatible.

Details

Affected packages:
github.com/openfga/openfga @ 1.5.4 (+6 more)