{"id":"GHSA-v9m8-9xxp-q492","summary":"Auth0-PHP SDK Deserialization of Untrusted Data vulnerability","details":"**Overview**\nThe Auth0 PHP SDK contains a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing malicious serialized data.\n\n**Am I Affected?**\nYou are affected by this vulnerability if you meet the following preconditions:\n\n1. Applications using the Auth0-PHP SDK, versions between 8.0.0-BETA3 to 8.3.0. \n2. Applications using the following SDKs that rely on the Auth0-PHP SDK versions between 8.0.0-BETA3 to 8.3.0:\n    a. Auth0/symfony,\n    b. Auth0/laravel-auth0,\n    c. Auth0/wordpress.\n\n**Fix**\nUpgrade Auth0/Auth0-PHP to 8.3.1.\n\n**Acknowledgement**\nOkta would like to thank Andreas Forsblom for discovering this vulnerability.","aliases":["CVE-2025-48951"],"modified":"2026-02-04T04:39:22.262305Z","published":"2025-06-04T20:31:39Z","related":["CVE-2025-48951"],"database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-06-04T20:31:39Z","nvd_published_at":"2025-06-03T21:15:21Z","cwe_ids":["CWE-502"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/auth0/auth0-PHP/security/advisories/GHSA-v9m8-9xxp-q492"},{"type":"WEB","url":"https://github.com/auth0/laravel-auth0/security/advisories/GHSA-c42h-56wx-h85q"},{"type":"WEB","url":"https://github.com/auth0/symfony/security/advisories/GHSA-98j6-67v3-mw34"},{"type":"WEB","url":"https://github.com/auth0/wordpress/security/advisories/GHSA-862m-5253-832r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48951"},{"type":"WEB","url":"https://github.com/auth0/auth0-PHP/commit/04b1f5daa8bdfebc5e740ec5ca0fb2df1648a715"},{"type":"PACKAGE","url":"https://github.com/auth0/auth0-PHP"}],"affected":[{"package":{"name":"auth0/auth0-php","ecosystem":"Packagist","purl":"pkg:composer/auth0/auth0-php"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0-BETA3"},{"fixed":"8.3.1"}]}],"versions":["8.0.0","8.0.0-BETA3","8.0.1","8.0.2","8.0.3","8.0.4","8.0.5","8.0.6","8.1.0","8.2.0","8.2.1","8.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-v9m8-9xxp-q492/GHSA-v9m8-9xxp-q492.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H"}]}