Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. filament/filament
  4. ›
  5. CVE-2025-67507

CVE-2025-67507: Filament multi-factor authentication (app) recovery codes can be used multiple times

December 9, 2025 (updated June 8, 2026)

A flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled.

If an attacker gains access to both the user’s password and their recovery codes, they can repeatedly complete MFA without the user’s app-based second factor. This weakens the expected security of MFA by turning recovery codes into a static, long-term bypass method.

References

  • github.com/advisories/GHSA-pvcv-q3q7-266g
  • github.com/filamentphp/filament/commit/87ff60ad9b6e16d4e14ee36a220b8917dd7b0815
  • github.com/filamentphp/filament/security/advisories/GHSA-pvcv-q3q7-266g
  • nvd.nist.gov/vuln/detail/CVE-2025-67507

Code Behaviors & Features

Detect and mitigate CVE-2025-67507 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 4.0.0 before 4.3.1

Fixed versions

  • 4.3.1

Solution

Upgrade to version 4.3.1 or above.

Impact 8.1 HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-287: Improper Authentication
  • CWE-288: Authentication Bypass Using an Alternate Path or Channel

Source file

packagist/filament/filament/CVE-2025-67507.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 07 Sep 2026 00:22:30 +0000.