PT-2025-28223 · Unknown · Better Auth

Imenyoo2

+1

·

Published

2025-07-07

·

Updated

2025-07-07

·

CVE-2025-53535

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Better Auth versions prior to 1.2.10
Description: An open redirect issue has been found in the originCheck middleware function of Better Auth, an authentication and authorization library for TypeScript. The affected routes include "/verify-email", "/reset-password/:token", "/delete-user/callback", "/magic-link/verify", and "/oauth-proxy-callback".
Recommendations: For versions prior to 1.2.10, update to version 1.2.10 to resolve the issue. As a temporary workaround, consider restricting access to the affected routes until the update can be applied.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-53535
GHSA-36RG-GFQ2-3H56

Affected Products

Better Auth