What is CVE-2025-71402?
CVE-2025-71392 is a vulnerability in the better-auth library's multi-session plugin, specifically in the /sign-out after-hook. It allows raw, unverified multi-session cookies to be forwarded to internalAdapter.deleteSessions without signature verification, potentially enabling unauthorized session deletion. Organizations using versions greater than 1.3.34 and before 1.4.0 should immediately upgrade to the latest version.
Azərbaycanca: CVE-2025-71392 zəifliyi 'better-auth' kitabxanasının multi-session plugin-inin `/sign-out` after-hook funksiyasında aşkarlanıb. Bu zəiflik, imza doğrulaması olunmamış cookie məlumatlarının birbaşa `internalAdapter.deleteSessions` funksiyasına ötürülməsinə səbəb olur ki, bu da icazəsiz sessiya silinməsinə yol aça bilər. 1.3.34-dən yuxarı, 1.4.0-dan əvvəlki versiyaları istifadə edən təşkilatlar dərhal ən son versiyaya yenilənməlidir.
FAQ2
In which library was CVE-2025-71392 discovered?
CVE-2025-71392 was discovered in the better-auth library.
Which versions are affected by CVE-2025-71392?
This vulnerability affects versions greater than 1.3.34 and before 1.4.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.