CVE-2025-48951

Source
https://cve.org/CVERecord?id=CVE-2025-48951
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48951.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-48951
Aliases
Related
Published
2025-06-03T20:52:35.064Z
Modified
2026-04-02T12:50:44.457643Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H CVSS Calculator
Summary
Auth0-PHP SDK Deserialization of Untrusted Data vulnerability
Details

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing malicious serialized data. Applications using the Auth0-PHP SDK are affected, as are applications using the Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs, because those SDKsrely on the Auth0-PHP SDK versions from 8.0.0-BETA3 until 8.14.0. Version 8.3.1 contains a patch for the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48951.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-502"
    ]
}
References

Affected packages

Git / github.com/auth0/auth0-php

Affected ranges

Type
GIT
Repo
https://github.com/auth0/auth0-php
Events

Affected versions

8.*
8.0.0
8.0.0-BETA3
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.2.0
8.2.1
8.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48951.json"