{"id":"CVE-2025-67507","aliases":["GHSA-pvcv-q3q7-266g"],"url":"https://o3.security/vulnerability/CVE-2025-67507","summary":"Filament's multi-factor authentication (app) recovery codes can be used multiple times","details":"A flaw in the handling of recovery codes for **app-based multi-factor authentication** allows the same recovery code to be reused indefinitely. This issue does **not** affect email-based MFA. It also only applies when recovery codes are enabled.\n\nIf an attacker gains access to both the user's password and their recovery codes, they can repeatedly complete MFA without the user's app-based second factor. This weakens the expected security of MFA by turning recovery codes into a static, long-term bypass method.","published":"2025-12-10T00:43:06.855Z","modified":"2026-08-12T03:51:29.262546500Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00352,"percentile":0.27899,"asOf":"2026-08-28"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"filament/filament","fixedVersion":"4.3.1"}],"fix":{"url":"https://github.com/filamentphp/filament/commit/87ff60ad9b6e16d4e14ee36a220b8917dd7b0815","label":"filamentphp/filament@87ff60a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67507.json"},{"type":"ADVISORY","url":"https://github.com/filamentphp/filament/security/advisories/GHSA-pvcv-q3q7-266g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67507"},{"type":"FIX","url":"https://github.com/filamentphp/filament/commit/87ff60ad9b6e16d4e14ee36a220b8917dd7b0815"},{"type":"PACKAGE","url":"https://github.com/filamentphp/filament"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.262546500Z"}}