HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2025-71403 — better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrig...

·Source: NIST NVD

Updated:

Executive Summary

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover.

Analysis

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover. CVSS Score: 7.1. Published: 2026-08-01T13:16:56.607.

Indicators of Compromise (1)

CVE (1)
CVE-2025-71403
Source Attribution

Originally published by NIST NVD on Aug 1, 2026. Verified by: NIST.

Related Threats