CVE-2025-71403

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 13:16

Updated : 2026-09-08 20:34


NVD link : CVE-2025-71403

Mitre link : CVE-2025-71403

CVE.ORG link : CVE-2025-71403


JSON object : View

Products Affected

No product.

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')