---
id: CVE-2025-15115
title: >-
  Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an
  authentication bypass vulnerability that allows unauthenticated attackers to
  access any user account by exploiting OAuth token validation flaws in the
  social login syst…
summary: >-
  Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an
  authentication bypass vulnerability that allows unauthenticated attackers to
  access any user account by exploiting OAuth token validation flaws in the
  social login syst…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-862
vendor: petlibro
product: petlibro
affected:
  - petlibro <= 1.7.31
published: '2026-01-04'
updated: '2026-07-20'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15115'
references:
  - url: 'https://bobdahacker.com/blog/petlibro'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/petlibro-smart-pet-feeder-platform-through-authentication-bypass-via-api-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00299
epssPercentile: 0.20037
ingestedAt: '2026-07-20T23:44:01.939Z'
---

## Overview

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login system. Attackers can send requests to /member/auth/thirdLogin with arbitrary Google IDs and phoneBrand parameters to obtain full session tokens and account access without proper OAuth verification.

## Affected

- `petlibro <= 1.7.31`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
