Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pvcv-q3q7-266g | Filament multi-factor authentication (app) recovery codes can be used multiple times |
Wed, 04 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:filamentphp:filament:*:*:*:*:*:*:*:* |
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filamentphp
Filamentphp filament |
|
| Vendors & Products |
Filamentphp
Filamentphp filament |
Wed, 10 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. This issue is fixed in version 4.3.1. | |
| Title | Filament's multi-factor authentication (app) recovery codes can be used multiple times | |
| Weaknesses | CWE-287 CWE-288 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-10T15:28:12.222Z
Reserved: 2025-12-08T21:36:28.780Z
Link: CVE-2025-67507
Updated: 2025-12-10T15:28:07.624Z
Status : Analyzed
Published: 2025-12-10T01:15:52.463
Modified: 2026-03-04T20:42:39.233
Link: CVE-2025-67507
No data.
OpenCVE Enrichment
Updated: 2025-12-10T17:48:51Z
Github GHSA