better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-01 13:16
Updated : 2026-09-08 20:34
NVD link : CVE-2025-71403
Mitre link : CVE-2025-71403
CVE.ORG link : CVE-2025-71403
JSON object : View
Products Affected
No product.
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
