blob: e60bb1f620a0670afe2531d6595c1c448f82d31c [file] [log] [blame]
id: GO-2025-3470
modules:
- module: github.com/openfga/openfga
versions:
- fixed: 1.8.5
vulnerable_at: 1.8.4
summary: OpenFGA Authorization Bypass in github.com/openfga/openfga
cves:
- CVE-2025-25196
ghsas:
- GHSA-g4v5-6f5p-m38j
references:
- advisory: https://github.com/openfga/openfga/security/advisories/GHSA-g4v5-6f5p-m38j
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-25196
- fix: https://github.com/openfga/openfga/commit/0aee4f47e0c642de78831ceb27bb62b116f49588
source:
id: GHSA-g4v5-6f5p-m38j
created: 2025-03-03T10:59:22.492296-05:00
review_status: UNREVIEWED