CVE-2025-48951 Details
Description
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing malicious serialized data. Applications using the Auth0-PHP SDK are affected, as are applications using the Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs, because those SDKsrely on the Auth0-PHP SDK versions from 8.0.0-BETA3 until 8.14.0. Version 8.3.1 contains a patch for the issue.
A critical vulnerability has been identified in the Auth0-PHP SDK, specifically in versions 8.0.0-BETA3 prior to 8.3.1. This vulnerability arises from insecure deserialization of cookie data. The issue allows a threat actor to send a specially crafted cookie containing malicious serialized data. Since the SDK processes cookie content without prior authentication, this vulnerability can be exploited in applications using Auth0-PHP, as well as those relying on Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs, which depend on vulnerable Auth0-PHP versions.
Upgrade the Auth0-PHP SDK to version 8.3.1 or later. For applications using Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress, ensure to update to the latest versions of those SDKs, which have incorporated the necessary patch.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 3, 2025CISA-ADP
Assessed Jun 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/auth0/auth0-PHP/commit/04b1f5daa8bdfebc5e740ec5ca0fb2df1648a715 | [email protected] | Source CodeVendor |
| https://github.com/auth0/auth0-PHP/security/advisories/GHSA-v9m8-9xxp-q492 | [email protected] | AdvisoryRemedyVendor |
| https://github.com/auth0/laravel-auth0/security/advisories/GHSA-c42h-56wx-h85q | [email protected] | AdvisoryRemedyVendor |
| https://github.com/auth0/symfony/security/advisories/GHSA-98j6-67v3-mw34 | [email protected] | AdvisoryRemedyVendor |
| https://github.com/auth0/wordpress/security/advisories/GHSA-862m-5253-832r | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Auth0/Auth0-PHP | >= 8.0.0-BETA3, <= 8.3.0 (semver) |
CPE
Remediation
| |
| Auth0/symfony | All versions |
CPE
Remediation
| |
| Auth0/laravel-auth0 | All versions |
CPE
Remediation
| |
| Auth0/wordpress | >= 7.0.0-BETA1, <= 7.2.1 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2025 | CVE Modified | [email protected] |
| Jun 4, 2025 | CVE Modified | [email protected] |
| Jun 3, 2025 | New CVE Received | [email protected] |
Volerion