PT-2025-23673 · Auth0 · Auth0/Wordpress+3
Kelvinzhu-Okta
·
Published
2025-06-03
·
Updated
2025-06-06
·
CVE-2025-48951
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Auth0-PHP versions 8.0.0-BETA3 through 8.14.0
Description
The issue is due to insecure deserialization of cookie data. If exploited, a threat actor could send a specially crafted cookie containing malicious serialized data, as the SDK processes cookie content without prior authentication. Applications using the Auth0-PHP SDK, as well as those using the Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs, are affected because they rely on the vulnerable Auth0-PHP SDK versions.
Recommendations
For versions 8.0.0-BETA3 through 8.14.0, update to version 8.14.0 to patch the security flaw. As a temporary workaround, consider restricting the processing of cookie content to minimize the risk of exploitation.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Auth0-Php
Auth0/Laravel-Auth0
Auth0/Symfony
Auth0/Wordpress