CVE-2025-71402

better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions without verifying the cookie signature (e.g., via getSignedCookie). An attacker can supply a forged _multi-* cookie to trigger deletion of arbitrary session tokens.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 13:16

Updated : 2026-09-08 20:34


NVD link : CVE-2025-71402

Mitre link : CVE-2025-71402

CVE.ORG link : CVE-2025-71402


JSON object : View

Products Affected

No product.

CWE
CWE-347

Improper Verification of Cryptographic Signature