Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68129

25
FAUCET Score

CVE-2025-68129 is a critical vulnerability in the Auth0-PHP SDK (versions 8.0.0 to 8.17.0) and dependent SDKs (Auth0/symfony, Auth0/laravel-auth0, Auth0/wordpress plugin) that improperly validates audience in access tokens, potentially allowing ID tokens to be accepted as access tokens. This flaw carries a CVSS score of 7.5 (HIGH), indicating a network-exploitable vulnerability with low attack complexity that could lead to high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Organizations using affected versions should upgrade to Auth0/Auth0-PHP version 8.18.0 immediately to mitigate the risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, < 8.18.0CPE matchmatch criteria
cpe:2.3:a:auth0:auth0-php:*:*:*:*:*:*:*:*
>= 7.0.0, < 7.20.0CPE matchmatch criteria
cpe:2.3:a:auth0:laravel-auth0:*:*:*:*:*:laravel:*:*
>= 5.0.0, < 5.6.0CPE matchmatch criteria
cpe:2.3:a:auth0:symfony:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.5.0CPE matchmatch criteria
cpe:2.3:a:auth0:wp-auth0:*:*:*:*:*:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

6.8MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 11th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: auth0/auth0-phpFixed in: 8.18.0
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-j2vm-wrq3-f7gfmedium

Auth0-PHP SDK has Improper Audience Validation

Dec 17, 2025

References

github.com / auth0/auth0-PHP/commit/7fe700053aee609718460c123f00f53c511f0f7f
Patch
github.com / auth0/auth0-PHP/releases/tag/8.18.0
ProductRelease Notes
github.com / auth0/auth0-PHP/security/advisories/GHSA-j2vm-wrq3-f7gf
Vendor Advisory
github.com / auth0/laravel-auth0/commit/a1c3344dc0e5a36e8f56c8cfc535728d3d7558f3
Patch
github.com / auth0/laravel-auth0/releases/tag/7.20.0
ProductRelease Notes
github.com / auth0/laravel-auth0/security/advisories/GHSA-7hh9-gp72-wh7h
Vendor Advisory
github.com / auth0/symfony/commit/0103d6f8dcef6996653fad1f823d1c167f472479
Patch
github.com / auth0/symfony/releases/tag/5.6.0
ProductRelease Notes
github.com / auth0/symfony/security/advisories/GHSA-f3r2-88mq-9v4g
Vendor Advisory
github.com / auth0/wordpress/commit/b207c6f7fd06507b90c4e6bcc18a857ef9e018de
Patch
github.com / auth0/wordpress/releases/tag/5.5.0
ProductRelease Notes
github.com / auth0/wordpress/security/advisories/GHSA-vvg7-8rmq-92g7
Vendor Advisory