PT-2025-23673 · Auth0 · Auth0/Laravel-Auth0+3

·

CVE-2025-48951

·

Published

2025-06-03

·

Updated

2025-06-06

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Auth0-PHP versions 8.0.0-BETA3 through 8.14.0
Description The issue is due to insecure deserialization of cookie data. If exploited, a threat actor could send a specially crafted cookie containing malicious serialized data, as the SDK processes cookie content without prior authentication. Applications using the Auth0-PHP SDK, as well as those using the Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs, are affected because they rely on the vulnerable Auth0-PHP SDK versions.
Recommendations For versions 8.0.0-BETA3 through 8.14.0, update to version 8.14.0 to patch the security flaw. As a temporary workaround, consider restricting the processing of cookie content to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48951
GHSA-862M-5253-832R
GHSA-98J6-67V3-MW34
GHSA-C42H-56WX-H85Q
GHSA-V9M8-9XXP-Q492

Affected Products

Auth0-Php
Auth0/Laravel-Auth0
Auth0/Symfony
Auth0/Wordpress