Authorization Bypass Vulnerability in OpenFGA by OpenFGA
CVE-2025-25196
What is CVE-2025-25196?
OpenFGA, a leading authorization and permission engine inspired by Google Zanzibar, suffers from an authorization bypass vulnerability in versions prior to v1.8.5. The vulnerability occurs when the Check API or ListObjects method is called using specific relational models that permit both public access and usersets of the same type. This scenario allows unauthorized users to gain access under specific conditions, potentially exposing sensitive data. Users are strongly recommended to upgrade to version v1.8.5, which ensures backward compatibility, as no effective workarounds exist.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openfga < 1.8.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
