CVE-2025-48371 Details
Description
OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users are affected under four specific conditions: First, calling Check API or ListObjects with an authorization model that has a relationship directly assignable by both type bound public access and userset; second, there are check or list object queries with contextual tuples for the relationship that can be directly assignable by both type bound public access and userset; third, those contextual tuples’s user field is an userset; and finally, type bound public access tuples are not assigned to the relationship. Users should upgrade to version 1.8.13 to receive a patch. The upgrade is backwards compatible.
A vulnerability allowing authorization bypass has been identified in OpenFGA versions 1.8.0 prior to 1.8.13. This issue arises when certain Check API and ListObjects calls are made under specific conditions, including the use of an authorization model with relationships assignable by both type-bound public access and userset, and the absence of type-bound public access tuples for the relationship. The vulnerability allows for incorrect authorization decisions, potentially leading to unauthorized access to objects or actions.
Users are advised to upgrade to OpenFGA version 1.8.13, which addresses this vulnerability. This upgrade is backwards compatible.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openfga helm charts | >= 0.2.16, < 0.2.32 |
CPE
Remediation
| |
| openfga openfga | >= 1.8.0, < 1.8.13 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 15, 2026 | Initial Analysis | [email protected] |
| May 22, 2025 | New CVE Received | [email protected] |