We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-48951

Auth0-PHP SDK Deserialization of Untrusted Data vulnerability



Description

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing malicious serialized data. Applications using the Auth0-PHP SDK are affected, as are applications using the Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs, because those SDKsrely on the Auth0-PHP SDK versions from 8.0.0-BETA3 until 8.14.0. Version 8.3.1 contains a patch for the issue.

Reserved 2025-05-28 | Published 2025-06-03 | Updated 2025-06-04 | Assigner GitHub_M


CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H

Problem types

CWE-502: Deserialization of Untrusted Data

Product status

>= 8.0.0-BETA3, < 8.3.1
affected

References

github.com/...h0-PHP/security/advisories/GHSA-v9m8-9xxp-q492

github.com/...-auth0/security/advisories/GHSA-c42h-56wx-h85q

github.com/...ymfony/security/advisories/GHSA-98j6-67v3-mw34

github.com/...dpress/security/advisories/GHSA-862m-5253-832r

github.com/...ommit/04b1f5daa8bdfebc5e740ec5ca0fb2df1648a715

cve.org (CVE-2025-48951)

nvd.nist.gov (CVE-2025-48951)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-48951

Support options

Helpdesk Chat, Email, Knowledgebase