Openfga · Openfga · CVE-2025-46331
**Name of the Vulnerable Software and Affected Versions**
OpenFGA versions 1.3.6 through 1.8.10
**Description**
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. The issue concerns an authorization bypass when certain `Check` and `ListObject` calls are executed. This problem has been corrected in version 1.8.11.
**Recommendations**
For versions 1.3.6 through 1.8.10, update to version 1.8.11 to resolve the issue.