PT-2025-18316 · Openfga · Openfga

Avinashs433

·

Published

2025-04-30

·

Updated

2025-05-20

·

CVE-2025-46331

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenFGA versions 1.3.6 through 1.8.10
Description OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. The issue concerns an authorization bypass when certain Check and ListObject calls are executed. This problem has been corrected in version 1.8.11.
Recommendations For versions 1.3.6 through 1.8.10, update to version 1.8.11 to resolve the issue.

Exploit

Fix

Incorrect Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-46331
ECHO-3774-CD30-2AE0
GHSA-W222-M46C-MGH6
GO-2025-3657
OPENSUSE-SU-2025:15135-1

Affected Products

Openfga