


Perceptive Security
SOC/SIEM Consultancy

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can…
Published:
31 July 2026 at 22:00:00
Alert date:
1 August 2026 at 14:11:12
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2025-71403 affects better-auth versions prior to 1.1.20, exposing a bypass vulnerability in the trustedOrigins validation logic. The flaw impacts handling of absolute URLs and wildcard domains, allowing attackers to craft malicious callbackURL parameters that evade origin validation checks. Successful exploitation triggers open redirects that can be leveraged to steal sensitive authentication tokens. The end result can be full account takeover of affected users. The vulnerability has been documented by NVD, GitHub Security Advisories, and VulnCheck. A fix is available in better-auth version 1.1.20 and later. Users are strongly advised to upgrade immediately to mitigate the risk of token theft and account compromise.
Technical details
Mitigation steps:
Affected products:
better-auth
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-71403
https://github.com/better-auth/better-auth/security/advisories/GHSA-vp58-j275-797x
https://www.vulncheck.com/advisories/better-auth-before-open-redirect-via-trustedorigins-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
