Headline
GHSA-7jp2-5h22-m432: Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import
Overview
In applications built with the Auth0-PHP SDK, the Bulk User Import endpoint does not validate the file path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs.
Am I affected?
You are affected by this vulnerability if you meet the following preconditions:
- Applications using the Auth0 Symfony SDK with versions between 2.0.2 and 5.4.1,
- Auth0 Symfony SDK uses the Auth0-PHP SDK with versions between 3.3.0 and 8.16.0.
Fix
Upgrade Auth0/symfony to version 5.5.0 or greater.
Acknowledgement
Okta would like to thank Mohamed Amine Saidani (pwni) for discovering this vulnerability.
- GitHub Advisory Database
- GitHub Reviewed
- GHSA-7jp2-5h22-m432
Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import
Low severity GitHub Reviewed Published Oct 1, 2025 in auth0/symfony • Updated Oct 1, 2025
Package
composer auth0/symfony (Composer)
Affected versions
>= 2.0.2, <= 5.4.1
Overview
In applications built with the Auth0-PHP SDK, the Bulk User Import endpoint does not validate the file path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs.
Am I affected?
You are affected by this vulnerability if you meet the following preconditions:
- Applications using the Auth0 Symfony SDK with versions between 2.0.2 and 5.4.1,
- Auth0 Symfony SDK uses the Auth0-PHP SDK with versions between 3.3.0 and 8.16.0.
Fix
Upgrade Auth0/symfony to version 5.5.0 or greater.
Acknowledgement
Okta would like to thank Mohamed Amine Saidani (pwni) for discovering this vulnerability.
References
- GHSA-7jp2-5h22-m432
- https://nvd.nist.gov/vuln/detail/CVE-2025-58769
- auth0/symfony@0b6dbd1
- https://github.com/auth0/symfony/releases/tag/5.5.0
Published to the GitHub Advisory Database
Oct 1, 2025