CVE-2025-68481 | fastapi-users FastAPI up to 15.0.1 /authorize generate_state_token improper authorization (GHSA-5j53-63w8-8625)

23:03 - 19 Dec 2025
A vulnerability classified as critical has been found in fastapi-users FastAPI up to 15.0.1. This impacts the function generate_state_token of the file /authorize. Performing manipulation results in improper authorization. This vulnerability is known as CVE-2025-68481. Remote exploitation of the attack is possible. No exploit is available. It is recommended to upgrade the affected component. Once again VulDB remains the best source for vulnerability data.

Article info: