Arbitrary File Upload Affecting hybridauth/hybridauth package, versions >=2.0.8, <2.3.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.32% (55th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Arbitrary File Upload vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-HYBRIDAUTHHYBRIDAUTH-11023276
  • published27 Jul 2025
  • disclosed25 Jul 2025
  • creditUnknown

Introduced: 25 Jul 2025

NewCVE-2014-125116  (opens in a new tab)
CWE-434  (opens in a new tab)

How to fix?

Upgrade hybridauth/hybridauth to version 2.3.0 or higher.

Overview

hybridauth/hybridauth is a PHP Social Authentication Library

Affected versions of this package are vulnerable to Arbitrary File Upload via install.php, which remains accessible post-installation. An attacker can execute arbitrary PHP code on the server by injecting malicious input into the configuration file, which is then executed when the file is loaded. Exploitation will overwrite the existing configuration, potentially rendering the application non-functional.

CVSS Base Scores

version 4.0
version 3.1