What is CVE-2025-71401?
CVE-2025-71401 affects better-auth npm package before version 1.4.2. When BETTER_AUTH_URL is not set, an attacker making the first request after server startup can set the baseURL, poisoning the router's base path and causing all routes to return 404. Upgrade to version 1.4.2 or later to mitigate this.
Azərbaycanca: CVE-2025-71401 better-auth npm paketində 1.4.2 versiyasından əvvəlki zəiflikdir. `BETTER_AUTH_URL` tənzimlənmədikdə, serverə ilk sorğunu edən şəxs baseURL-i kənardan konfiqurasiya edə bilər və bu, bütün route-ların 404 qaytarmasına səbəb olur. Təsirə məruz qalmamaq üçün paketi ən azı 1.4.2 versiyasına yeniləmək lazımdır.
FAQ2
Which versions of the better-auth package are affected by CVE-2025-71401?
This vulnerability affects all versions of the better-auth npm package prior to version 1.4.2.
How can I mitigate CVE-2025-71401?
To avoid being affected, you should upgrade the better-auth package to version 1.4.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.