CVE-2025-71403 PUBLISHED

better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass

Assigner: VulnCheck
Reserved: 18.07.2026 Published: 01.08.2026 Updated: 01.08.2026

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor better-auth
Product better-auth
Versions Default: unaffected
  • affected from 0 to 1.1.20 (excl.)
  • Version 1.1.20 is unaffected

Credits

  • castilho101 reporter

References

Problem Types

  • URL Redirection to Untrusted Site ('Open Redirect') CWE