What is CVE-2025-71403?
A bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains exists in better-auth versions prior to 1.1.20. Attackers can construct malicious callbackURL parameters to bypass origin checks and trigger open redirects, leading to sensitive token theft and account takeover. Users must immediately upgrade to the latest version and carefully validate callbackURL parameters.
Azərbaycanca: better-auth 1.1.20-dən əvvəlki versiyalarda trustedOrigins yoxlama məntiqində absolute URL-lər və wildcard domenlərə təsir edən bir bypass zəifliyi aşkar edilmişdir. Təcavüzkarlar callbackURL parametri vasitəsilə mənşə yoxlamalarını yan keçərək token oğurluğu ilə hesab ələ keçirə bilərlər. İstifadəçilər dərhal ən son versiyaya yeniləməli və callbackURL parametrlərini diqqətlə yoxlamalıdırlar.
FAQ2
Which versions of better-auth are affected by the vulnerability that allows bypassing trustedOrigins checks via callbackURL?
This bypass vulnerability affects better-auth versions prior to 1.1.20.
How can an attacker exploit the callbackURL parameter using this vulnerability?
Attackers can construct malicious callbackURL parameters to bypass origin checks, leading to token theft and account takeover.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.