{"id":"CVE-2025-55213","aliases":["GHSA-mgh9-4mwp-fg55","GO-2025-3894"],"url":"https://o3.security/vulnerability/CVE-2025-55213","summary":"OpenFGA Authorization Bypass (Check)","details":"### Overview\nOpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <= docker <= v.1.9.4) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed.\n\n### Am I Affected?\nYou are affected by this vulnerability if you are using OpenFGA v1.9.3 to v1.9.4, specifically under the following preconditions:\n- Calling Check API or ListObjects with an [authorization model](https://openfga.dev/docs/concepts#what-is-an-authorization-model) that has a relationship directly assignable by more than 1 [userset](https://openfga.dev/docs/modeling/building-blocks/usersets) with same [type](https://openfga.dev/docs/concepts#what-is-a-type), and\n- There are check or list object queries that rely on the above relationship, and\n- You have userset tuples that are assigned to the above relationship\n\n\n### Fix\nUpgrade to v1.9.5. This upgrade is backwards compatible.\n\n### Workaround\nDowngrade to v1.9.2 with enable-check-optimizations removed from OPENFGA_EXPERIMENTALS\n\n### Acknowledgments\nOpenFGA would like Dominic Harries and rrozza-apolitical to thank for discovering this vulnerability.","published":"2025-08-18T19:23:33.684Z","modified":"2026-08-12T03:51:42.616366762Z","cvss":null,"epss":{"score":0.00316,"percentile":0.23787,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openfga/openfga","fixedVersion":"1.9.5"}],"fix":{"url":"https://github.com/openfga/openfga/commit/1a7e0e37fc4777c824b2386cac4867a66f3480b0","label":"openfga/openfga@1a7e0e3"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55213.json"},{"type":"ADVISORY","url":"https://github.com/openfga/openfga/security/advisories/GHSA-mgh9-4mwp-fg55"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55213"},{"type":"FIX","url":"https://github.com/openfga/openfga/commit/1a7e0e37fc4777c824b2386cac4867a66f3480b0"},{"type":"PACKAGE","url":"https://github.com/openfga/openfga"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2025-3894"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.616366762Z"}}