CVE-2024-56734: Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
Summary An open redirect vulnerability has been identified in the verify email endpoint of Better Auth, potentially allowing attackers to redirect users to malicious websites. This issue affects users relying on email verification links generated by the library.
Affected Versions - All versions prior to v1.1.6.
Impact Attackers could craft malicious email verification links that exploit the redirect functionality to send users to untrusted domains. This can result in:
- Phishing attacks – Users may unknowingly enter sensitive information on fake login pages. - Reputation damage – Trust issues for applications using Better Auth.
Vulnerability Details The verify email callback endpoint accepts a callbackURL parameter. Unlike other verification methods, email verification only uses JWT to verify and redirect without proper validation of the target domain. The origin checker is bypassed in this scenario because it only checks for POST requests. An attacker can manipulate this parameter to redirect users to arbitrary URLs controlled by the attacker.
Example Exploit: https://example.com/auth/verify-email?token=abcd1234&callbackURL=https://malicious-site.com
Patches Upgrade to Better Auth v1.1.6 or later. This version enforces domain validation for callbackURL for /verify-email path and for all other GET endpoints.
Workarounds You can also use hooks to pre-check URLs in your auth instance to prevent this without upgrading:
ts const auth = betterAuth({ hooks: { before: (ctx) => { if (ctx.path === "/verify-email") { const callbackURL = ctx.query.callbackURL; // Check if this is a trusted callback URL or not } } } })
Other sources
Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better Auth prior to v1.1.6, potentially allowing attackers to redirect users to malicious websites. This issue affects users relying on email verification links generated by the library. The verify email callback endpoint accepts a callbackURL parameter. Unlike other verification methods, email verification only uses JWT to verify and redirect without proper validation of the target domain. The origin checker is bypassed in this scenario because it only checks for POST requests. An attacker can manipulate this parameter to redirect users to arbitrary URLs controlled by the attacker. Version 1.1.6 contains a patch for the issue.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56734?
CVE-2024-56734 has a severity rating that allows attackers to potentially redirect users to malicious websites.
How do I fix CVE-2024-56734?
To resolve CVE-2024-56734, upgrade to version 1.1.6 or higher of the Better Auth package.
What kind of vulnerability is CVE-2024-56734?
CVE-2024-56734 is classified as an open redirect vulnerability affecting the verify email endpoint.
Who is affected by CVE-2024-56734?
CVE-2024-56734 affects users relying on email verification links generated by the Better Auth library.
What can attackers achieve with CVE-2024-56734?
Attackers can exploit CVE-2024-56734 to redirect users to potentially harmful or malicious websites.