CVE-2025-58769 - CVE House
Back to Database
Status published Low CVE-2025-58769

auth0-PHP: Improper File Type Handling in Bulk User Import

Vulnerability Description

auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications built with the SDK does not validate the file-path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs. The vulnerability affects any application that either directly uses the Auth0-PHP SDK (versions 3.3.0–8.16.0) or indirectly relies on those versions through the Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs. This issue is fixed in version 8.17.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58769

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

laravel-auth0
Vulnerable Versions:
>= 3.3.0, < 8.17.0

Timeline

Official Publish: October 1st, 2025
Last Modified: October 1st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)