What is CVE-2025-71399?
CVE-2025-71399: Better Auth is vulnerable to a path normalization issue in the rou3 router library, where multiple slashes in paths (e.g., //path) are treated identically to single-slash paths. This can allow attackers to bypass routes. Users should upgrade to Better Auth version 1.4.5 or later, which bundles the fixed rou3 version.
Azərbaycanca: CVE-2025-71399: Better Auth kimlik doğrulama kitabxanası, rou3 marşrut kitabxanasındakı boşluğa görə path normalization zəifliyinə məruz qalır. //path kimi çoxlu slash-lı yolların tək slash-la eyni hesab edilməsi hücumçuya marşrut yan keçmə riski yarada bilər. İstifadəçilərə dərhal Better Auth 1.4.5 və ya daha yuxarı versiyaya yeniləmələri tövsiyə olunur.
FAQ2
In which Better Auth version is CVE-2025-71399 fixed?
This vulnerability is fixed in Better Auth version 1.4.5 and later. Users are advised to upgrade immediately.
What component causes the CVE-2025-71399 vulnerability?
The vulnerability stems from a path normalization issue in the rou3 router library, where paths with multiple slashes are treated identically to single-slash paths.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.