PT-2025-62896 · Unknown · Better Auth
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
better-auth versions 1.3.35 through 1.3.99
Description
The multi-session plugin contains a flaw in the
/sign-out endpoint after-hook. The system trusts raw multi-session cookies and forwards extracted values to the deleteSessions() function within the internalAdapter without verifying the cookie signature, such as by using getSignedCookie(). This allows an attacker to provide a forged multi-* cookie to trigger the deletion of arbitrary session tokens.Recommendations
Update better-auth to version 1.4.0 or later.
As a temporary mitigation, restrict the use of the multi-session plugin until the update is applied.
Exploit
Fix
Improper Verification of Cryptographic Signature
Insufficient Verification of Data Authenticity
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Better Auth