https://reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/: Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
Published Oct 20, 2025
·Updated
Affected Software
1 affected component
better-auth better-auth
Frequently Asked Questions
1
What is the severity of CVE-2025-61928?
CVE-2025-61928 is classified as a critical vulnerability due to its potential for complete account takeover.
2
How do I fix CVE-2025-61928?
To fix CVE-2025-61928, ensure that your Better-Auth configuration disallows unauthenticated API key creation.
3
What applications are affected by CVE-2025-61928?
CVE-2025-61928 affects applications using Better-Auth with API keys enabled.
4
What can attackers do with CVE-2025-61928?
Attackers can exploit CVE-2025-61928 to create unauthenticated API keys, leading to unauthorized access and account takeover.
5
Is there a patch available for CVE-2025-61928?
As of now, a specific patch for CVE-2025-61928 has not been mentioned, so users should monitor official channels for updates.