Reflected XSS Vulnerability in Better-Auth Product by Better-Auth
CVE-2025-71404
5.1MEDIUM
What is CVE-2025-71404?
A reflected cross-site scripting (XSS) vulnerability has been identified in the Better-Auth product. Specifically, in versions after v0.0.2 and before 1.1.16, an attacker can exploit this vulnerability via the '/api/auth/error' endpoint. The underlying issue arises from the improper sanitization of the 'error' URL parameter, allowing arbitrary JavaScript code to execute in the users' browsers if they navigate to a specially crafted URL. This vulnerability poses significant security risks, including session hijacking and unauthorized actions performed on behalf of the user. It is crucial for users to upgrade to version 1.1.16 or later to mitigate potential threats.
Affected Version(s)
better-auth 0 < 1.1.16
better-auth 1.1.16
