GHSA-9mh6-g99m-ppcw
auth0-PHP SDK Does Not Properly Handle File Types in Bulk User Import
Quick fix
GHSA-9mh6-g99m-ppcw — auth0/auth0-php: upgrade to the fixed version with the command below.
composer require auth0/auth0-php:^8.17.0Details
### Overview In applications built with the Auth0-PHP SDK, the Bulk User Import endpoint does not validate the file path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs.
### Am I affected? You are affected by this vulnerability if you meet the following preconditions: 1. Applications using the Auth0-PHP SDK, versions between v3.3.0 and v8.16.0, or 2. Applications using the following SDKs that rely on the Auth0-PHP SDK versions between v3.3.0 and v8.16.0: a. Auth0/symfony, b. Auth0/laravel-auth0, c. Auth0/wordpress.
### Fix Upgrade Auth0/Auth0-PHP to version 8.17.0 or greater.
### Acknowledgement Okta would like to thank Mohamed Amine Saidani (pwni) for discovering this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.3.0Fixed in: 8.17.0composer require auth0/auth0-php:^8.17.0References
- https://github.com/auth0/auth0-PHP/security/advisories/GHSA-9mh6-g99m-ppcw[WEB]
- https://github.com/auth0/laravel-auth0/security/advisories/GHSA-hjfh-5jmm-xr24[WEB]
- https://github.com/auth0/symfony/security/advisories/GHSA-7jp2-5h22-m432[WEB]
- https://github.com/auth0/wordpress/security/advisories/GHSA-w22c-pw5m-482x[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-58769[ADVISORY]
- https://github.com/auth0/auth0-PHP/commit/9026da58f5c381cd4cb5932de829eff6eacbb65c[WEB]
- https://github.com/auth0/auth0-PHP[PACKAGE]
- https://github.com/auth0/auth0-PHP/releases/tag/8.17.0[WEB]