Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-7jp2-5h22-m432: Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import

Overview

In applications built with the Auth0-PHP SDK, the Bulk User Import endpoint does not validate the file path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs.

Am I affected?

You are affected by this vulnerability if you meet the following preconditions:

  1. Applications using the Auth0 Symfony SDK with versions between 2.0.2 and 5.4.1,
  2. Auth0 Symfony SDK uses the Auth0-PHP SDK with versions between 3.3.0 and 8.16.0.

Fix

Upgrade Auth0/symfony to version 5.5.0 or greater.

Acknowledgement

Okta would like to thank Mohamed Amine Saidani (pwni) for discovering this vulnerability.

ghsa
#vulnerability#git#php#perl#auth
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. GHSA-7jp2-5h22-m432

Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import

Low severity GitHub Reviewed Published Oct 1, 2025 in auth0/symfony • Updated Oct 1, 2025

Package

composer auth0/symfony (Composer)

Affected versions

>= 2.0.2, <= 5.4.1

Overview

In applications built with the Auth0-PHP SDK, the Bulk User Import endpoint does not validate the file path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs.

Am I affected?

You are affected by this vulnerability if you meet the following preconditions:

  1. Applications using the Auth0 Symfony SDK with versions between 2.0.2 and 5.4.1,
  2. Auth0 Symfony SDK uses the Auth0-PHP SDK with versions between 3.3.0 and 8.16.0.

Fix

Upgrade Auth0/symfony to version 5.5.0 or greater.

Acknowledgement

Okta would like to thank Mohamed Amine Saidani (pwni) for discovering this vulnerability.

References

  • GHSA-7jp2-5h22-m432
  • https://nvd.nist.gov/vuln/detail/CVE-2025-58769
  • auth0/symfony@0b6dbd1
  • https://github.com/auth0/symfony/releases/tag/5.5.0

Published to the GitHub Advisory Database

Oct 1, 2025

ghsa: Latest News

GHSA-86rg-8hc8-v82p: LibreNMS is vulnerable to Reflected-XSS in `report_this` function