top of page
perceptive_background_267k.jpg

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can…

Published:

31 July 2026 at 22:00:00

Alert date:

1 August 2026 at 14:11:12

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2025-71403 affects better-auth versions prior to 1.1.20, exposing a bypass vulnerability in the trustedOrigins validation logic. The flaw impacts handling of absolute URLs and wildcard domains, allowing attackers to craft malicious callbackURL parameters that evade origin validation checks. Successful exploitation triggers open redirects that can be leveraged to steal sensitive authentication tokens. The end result can be full account takeover of affected users. The vulnerability has been documented by NVD, GitHub Security Advisories, and VulnCheck. A fix is available in better-auth version 1.1.20 and later. Users are strongly advised to upgrade immediately to mitigate the risk of token theft and account compromise.

Technical details

Mitigation steps:

Affected products:

better-auth

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page