PT-2025-28223 · Unknown · Better Auth
Imenyoo2
+1
·
Published
2025-07-07
·
Updated
2025-07-07
·
CVE-2025-53535
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Better Auth versions prior to 1.2.10
Description:
An open redirect issue has been found in the originCheck middleware function of Better Auth, an authentication and authorization library for TypeScript. The affected routes include "/verify-email", "/reset-password/:token", "/delete-user/callback", "/magic-link/verify", and "/oauth-proxy-callback".
Recommendations:
For versions prior to 1.2.10, update to version 1.2.10 to resolve the issue. As a temporary workaround, consider restricting access to the affected routes until the update can be applied.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Better Auth