OpenFGA v1.4.0 to v1.11.0 (openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed.
You are affected by this vulnerability if you meet the following preconditions:
- You are using OpenFGA v1.4.0 to v1.11.0
- The model has a a relation directly assignable by a type bound pubic access with condition
- The same relation is not assignable by a type bound public access without condition
- You have a type assigned for the same relation that is a type bound public access without condition
Upgrade to v1.11.1. This upgrade is backwards compatible.
None
| Score | Percentile |
|---|---|
| 0.06% | 18.41% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 5.8 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-2c64-vmv2-hgfc ↗ |
| CVE | CVE-2025-64751 ↗ |
| CWE id | Name |
|---|---|
| CWE-285 | Improper Authorization |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| go | github.com/openfga/openfga | >= 1.4.0, < 1.11.1 | 1.11.1 | — |