CVE-2025-71403: better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
better-authto a version that resolves this vulnerability.Fixed in 1.1.20
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71403?
The severity of CVE-2025-71403 is high with a CVSS score of 7.1.
How do I fix CVE-2025-71403?
To fix CVE-2025-71403, upgrade to better-auth version 1.1.20 or later.
What impact does CVE-2025-71403 have on my system?
CVE-2025-71403 can allow attackers to perform open redirects, which may lead to account takeover by stealing sensitive tokens.
What software is affected by CVE-2025-71403?
CVE-2025-71403 affects all versions of better-auth prior to 1.1.20.
Can I mitigate CVE-2025-71403 without an upgrade?
Mitigation options without an upgrade are limited, and the best course of action is to apply the upgrade to eliminate the vulnerability.