GHSA-c72g-53hw-82q7
OpenFGA Authorization Bypass
Quick fix
GHSA-c72g-53hw-82q7 — github.com/openfga/openfga: upgrade to the fixed version with the command below.
go get github.com/openfga/openfga@v1.8.13Details
### Overview OpenFGA v1.8.0 to v1.8.12 ( openfga-0.2.16 <= Helm chart <= openfga-0.2.31, v1.8.0 <= docker <= v.1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.
### Am I Affected? If you are using OpenFGA v1.8.0 to v1.8.12, specifically under the following conditions, you are affected by this authorization bypass vulnerability: - Calling Check API or ListObjects with an [authorization model](https://openfga.dev/docs/concepts#what-is-an-authorization-model) that has a relationship directly assignable by both [type bound public access](https://openfga.dev/docs/concepts#what-is-type-bound-public-access) and [userset](https://openfga.dev/docs/modeling/building-blocks/usersets), and - There are check or list object queries with [contextual tuples](https://openfga.dev/docs/interacting/contextual-tuples) for the relationship that can be directly assignable by both [type bound public access](https://openfga.dev/docs/concepts#what-is-type-bound-public-access) and [userset](https://openfga.dev/docs/modeling/building-blocks/usersets), and - Those contextual tuples’s user field is an userset, and - Type bound public access tuples are not assigned to the relationship
### Fix Upgrade to v1.8.13. This upgrade is backwards compatible.
### Acknowledgments OpenFGA would like to thank @udyvish for discovering this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
1.8.0Fixed in: 1.8.13go get github.com/openfga/openfga@v1.8.13References
- https://github.com/openfga/openfga/security/advisories/GHSA-c72g-53hw-82q7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-48371[ADVISORY]
- https://github.com/openfga/openfga/commit/e5960d4eba92b723de8ff3a5346a07f50c1379ca[WEB]
- https://github.com/openfga/openfga[PACKAGE]
- https://pkg.go.dev/vuln/GO-2025-3707[WEB]