LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2025-71403

Published
CVSS7.1
Severityhigh
WeaknessCWE-601
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

Description

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-71403

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-71403.