PT-2025-28223 · Unknown · Better Auth

·

CVE-2025-53535

·

Published

2025-07-07

·

Updated

2025-07-07

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Better Auth versions prior to 1.2.10
Description: An open redirect issue has been found in the originCheck middleware function of Better Auth, an authentication and authorization library for TypeScript. The affected routes include "/verify-email", "/reset-password/:token", "/delete-user/callback", "/magic-link/verify", and "/oauth-proxy-callback".
Recommendations: For versions prior to 1.2.10, update to version 1.2.10 to resolve the issue. As a temporary workaround, consider restricting access to the affected routes until the update can be applied.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-53535
GHSA-36RG-GFQ2-3H56

Affected Products

Better Auth