Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. This issue is fixed in version 4.3.1.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filamentphp
Filamentphp filament |
|
| Vendors & Products |
Filamentphp
Filamentphp filament |
Wed, 10 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. This issue is fixed in version 4.3.1. | |
| Title | Filament's multi-factor authentication (app) recovery codes can be used multiple times | |
| Weaknesses | CWE-287 CWE-288 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-10T00:43:06.855Z
Updated: 2025-12-10T15:28:12.222Z
Reserved: 2025-12-08T21:36:28.780Z
Link: CVE-2025-67507
Updated: 2025-12-10T15:28:07.624Z
Status : Received
Published: 2025-12-10T01:15:52.463
Modified: 2025-12-10T01:15:52.463
Link: CVE-2025-67507
No data.