• Vulnerability/
  • https://reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/

https://reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/: Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)

Published Oct 20, 2025
·
Updated

Affected Software

1 affected component
better-auth better-auth

Frequently Asked Questions

1

What is the severity of CVE-2025-61928?

CVE-2025-61928 is classified as a critical vulnerability due to its potential for complete account takeover.

2

How do I fix CVE-2025-61928?

To fix CVE-2025-61928, ensure that your Better-Auth configuration disallows unauthenticated API key creation.

3

What applications are affected by CVE-2025-61928?

CVE-2025-61928 affects applications using Better-Auth with API keys enabled.

4

What can attackers do with CVE-2025-61928?

Attackers can exploit CVE-2025-61928 to create unauthenticated API keys, leading to unauthorized access and account takeover.

5

Is there a patch available for CVE-2025-61928?

As of now, a specific patch for CVE-2025-61928 has not been mentioned, so users should monitor official channels for updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203