Reflected XSS Vulnerability in Better-Auth Product by Better-Auth
CVE-2025-71404

5.1MEDIUM

Key Information:

Vendor
CVE Published:
1 August 2026

What is CVE-2025-71404?

A reflected cross-site scripting (XSS) vulnerability has been identified in the Better-Auth product. Specifically, in versions after v0.0.2 and before 1.1.16, an attacker can exploit this vulnerability via the '/api/auth/error' endpoint. The underlying issue arises from the improper sanitization of the 'error' URL parameter, allowing arbitrary JavaScript code to execute in the users' browsers if they navigate to a specially crafted URL. This vulnerability poses significant security risks, including session hijacking and unauthorized actions performed on behalf of the user. It is crucial for users to upgrade to version 1.1.16 or later to mitigate potential threats.

Affected Version(s)

better-auth 0 < 1.1.16

better-auth 1.1.16

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eriner
.