CVE-2025-48951: Auth0-PHP SDK Deserialization of Untrusted Data vulnerability

Published Jun 3, 2025
·
Updated

Overview The Auth0 PHP SDK contains a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing malicious serialized data.

Am I Affected? You are affected by this vulnerability if you meet the following preconditions:

1. Applications using the Auth0-PHP SDK, versions between 8.0.0-BETA3 to 8.3.0. 2. Applications using the following SDKs that rely on the Auth0-PHP SDK versions between 8.0.0-BETA3 to 8.3.0: a. Auth0/symfony, b. Auth0/laravel-auth0, c. Auth0/wordpress.

Fix Upgrade Auth0/Auth0-PHP to 8.3.1.

Acknowledgement Okta would like to thank Andreas Forsblom for discovering this vulnerability.

Other sources

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing malicious serialized data. Applications using the Auth0-PHP SDK are affected, as are applications using the Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs, because those SDKsrely on the Auth0-PHP SDK versions from 8.0.0-BETA3 until 8.14.0. Version 8.3.1 contains a patch for the issue.

NVD

Affected Software

5 affected componentsFixes available
Auth0 Auth0-PHP<8.14.0
Auth0 Auth0/symfony<8.14.0
Auth0 Auth0/laravel-auth0<8.14.0
Auth0 Auth0/wordpress<8.14.0
composer/auth0/auth0-php>=8.0.0-BETA3<8.3.1
8.3.1

Event History

Jun 3, 2025
CVE Published
via MITRE·08:52 PM
Data Sourced
via MITRE·08:52 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Jun 4, 2025
Advisory Published
via GitHub·08:31 PM
Data Sourced
via GitHub·08:31 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-48951?

CVE-2025-48951 has been classified as a high-severity vulnerability due to the potential for unauthorized access through insecure deserialization of cookie data.

2

How do I fix CVE-2025-48951?

To mitigate CVE-2025-48951, upgrade to Auth0-PHP version 8.14.0 or later where the vulnerability has been addressed.

3

What impact does CVE-2025-48951 have on my application?

CVE-2025-48951 could allow attackers to manipulate cookie data, potentially leading to unauthorized user authentication and data exposure.

4

Which versions of Auth0-PHP are affected by CVE-2025-48951?

Auth0-PHP versions prior to 8.14.0 are affected by CVE-2025-48951.

5

Is there a known exploit for CVE-2025-48951?

As of now, there are no publicly known exploits for CVE-2025-48951, but the vulnerability presents a risk if not patched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203