File Path Validation Issue in Auth0-PHP SDK by Auth0
CVE-2025-58769
What is CVE-2025-58769?
The Auth0-PHP SDK experiences a significant vulnerability in versions 3.3.0 through 8.16.0, where the Bulk User Import endpoint fails to properly validate file-path wrappers or their values. This oversight allows applications leveraging the SDK to potentially accept arbitrary file paths or URLs, posing security risks. Affected applications include those directly utilizing Auth0-PHP or indirectly relying on its functionalities via Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs. Users should upgrade to version 8.17.0 to mitigate this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
laravel-auth0 >= 3.3.0, < 8.17.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved