PT-2025-62898 · Unknown · Better Auth

·

CVE-2025-71404

·

Published

2025-02-05

·

Updated

2026-08-01

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions better-auth versions 0.0.3 through 1.1.15
Description A reflected cross-site scripting (XSS) issue exists on the '/api/auth/error' endpoint. The application reflects the value of the error URL parameter as HTML without proper neutralization, allowing an attacker to execute arbitrary JavaScript in the user's browser by inducing them to visit a specially-crafted URL.
Recommendations Update to version 1.1.16. As a temporary workaround, restrict access to the '/api/auth/error' endpoint or avoid using the error parameter until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71404
GHSA-9X4V-XFQ5-M8X5

Affected Products

Better Auth