OpenFGA Authorization Bypass
Package
Affected versions
>= 1.8.0, < 1.8.13
Patched versions
1.8.13
Description
Published by the National Vulnerability Database
May 22, 2025
Published to the GitHub Advisory Database
May 23, 2025
Reviewed
May 23, 2025
Last updated
May 28, 2025
Overview
OpenFGA v1.8.0 to v1.8.12 ( openfga-0.2.16 <= Helm chart <= openfga-0.2.30, v1.8.0 <= docker <= v.1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.
Am I Affected?
If you are using OpenFGA v1.8.0 to v1.8.12, specifically under the following conditions, you are affected by this authorization bypass vulnerability:
Fix
Upgrade to v1.8.13. This upgrade is backwards compatible.
Acknowledgments
Okta would like to thank @udyvish for discovering this vulnerability.
References