VYPR

better-auth

by GitHub

CVEs (2)

  • CVE-2025-71401Aug 2, 2026
    risk 0.00cvss epss 0.00

    better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to…

  • CVE-2025-71403Aug 1, 2026
    risk 0.00cvss epss 0.00

    better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive…