{"id":"CVE-2025-67507","aliases":["GHSA-pvcv-q3q7-266g"],"url":"https://o3.security/vulnerability/CVE-2025-67507","summary":"Filament's multi-factor authentication (app) recovery codes can be used multiple times","details":"Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. This issue is fixed in version 4.3.1.","published":"2025-12-10T00:43:06.855Z","modified":"2026-08-08T03:47:57.661455430Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"filament/filament","fixedVersion":"4.3.1"}],"fix":{"url":"https://github.com/filamentphp/filament/commit/87ff60ad9b6e16d4e14ee36a220b8917dd7b0815","label":"filamentphp/filament@87ff60a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67507.json"},{"type":"ADVISORY","url":"https://github.com/filamentphp/filament/security/advisories/GHSA-pvcv-q3q7-266g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67507"},{"type":"FIX","url":"https://github.com/filamentphp/filament/commit/87ff60ad9b6e16d4e14ee36a220b8917dd7b0815"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:57.661455430Z"}}