{"id":"CVE-2024-31452","aliases":["GHSA-8cph-m685-6v6r","GO-2024-2729"],"url":"https://o3.security/vulnerability/CVE-2024-31452","summary":"OpenFGA Authorization Bypass","details":"# Overview\nSome end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs.\n\n# Am I Affected?\nYou are very likely affected if your model involves exclusion (e.g. `a but not b`) or intersection (e.g. `a and b`) and you have any cyclical relationships. If you are using these, please update as soon as possible.\n\n# Fix\nUpdate to v1.5.3\n\n# Backward Compatibility\nThis update is backward compatible.","published":"2024-04-16T21:40:58.856Z","modified":"2026-08-12T03:51:21.129954247Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openfga/openfga","fixedVersion":"1.5.3"}],"fix":{"url":"https://github.com/openfga/openfga/commit/b6a6d99b2bdbf8c3781503989576076289f48ed2","label":"openfga/openfga@b6a6d99"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31452.json"},{"type":"ADVISORY","url":"https://github.com/openfga/openfga/security/advisories/GHSA-8cph-m685-6v6r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31452"},{"type":"FIX","url":"https://github.com/openfga/openfga/commit/b6a6d99b2bdbf8c3781503989576076289f48ed2"},{"type":"PACKAGE","url":"https://github.com/openfga/openfga"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.129954247Z"}}