Authorization Bypass Vulnerability in OpenFGA by OpenFGA
CVE-2025-25196
5.8MEDIUM
What is CVE-2025-25196?
OpenFGA, a leading authorization and permission engine inspired by Google Zanzibar, suffers from an authorization bypass vulnerability in versions prior to v1.8.5. The vulnerability occurs when the Check API or ListObjects method is called using specific relational models that permit both public access and usersets of the same type. This scenario allows unauthorized users to gain access under specific conditions, potentially exposing sensitive data. Users are strongly recommended to upgrade to version v1.8.5, which ensures backward compatibility, as no effective workarounds exist.
Affected Version(s)
openfga < 1.8.5