PT-2025-62893 · Npm+1 · Better-Call+2

·

CVE-2025-71399

·

Published

2025-12-16

·

Updated

2026-08-02

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Better Auth versions prior to 1.4.5
Description Better Auth utilizes the better-call library, which depends on the rou3 router. In affected versions of rou3, paths are normalized by removing empty segments, causing paths such as /path, //path, and ///path to resolve to the same route. This behavior allows attackers to bypass the disabledPaths configuration and path-based rate limits by including extra slashes in the URL path. This issue does not affect deployments where the proxy or platform automatically normalizes URLs by collapsing multiple slashes.
Recommendations Update Better Auth to version 1.4.5 or later. Ensure the proxy normalizes URLs by collapsing multiple slashes before they reach the handler.

Exploit

Fix

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71399
GHSA-X732-6J76-QMHM

Affected Products

Better Auth
Better-Call
Rou3