What is CVE-2025-71400?
CVE-2025-71400 is an Insecure Direct Object Reference vulnerability in better-auth passkey versions before 1.4.0, allowing authenticated attackers to delete arbitrary passkeys via the passkey deletion endpoint. Affected users should immediately upgrade to version 1.4.0 to mitigate the risk.
Azərbaycanca: CVE-2025-71400 better-auth passkey-in 1.4.0-dən əvvəlki versiyalarında IDOR zəifliyidir. Autentifikasiya olunmuş ixtiyari istifadəçi passkey silmə endpoint-inə xüsusi sorğu göndərərək başqalarının passkey-lərini silə bilər, təsirlənən sistemlər dərhal 1.4.0 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What is CVE-2025-71400 and which product does it affect?
CVE-2025-71400 is an IDOR (Insecure Direct Object Reference) vulnerability found in better-auth passkey versions before 1.4.0. This vulnerability allows any authenticated attacker to delete arbitrary passkeys via the passkey deletion endpoint.
How can I mitigate CVE-2025-71400?
Affected systems should be immediately upgraded to better-auth passkey version 1.4.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.