{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/better-auth--1.1.20/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2025-71403"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["better-auth (\u003c 1.1.20)"],"_cs_severities":["high"],"_cs_tags":["authentication","web-security","open-redirect","cve-2025-71403"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe authentication library better-auth is vulnerable to an open redirect flaw in versions prior to 1.1.20 due to improper validation of the 'trustedOrigins' logic. This security weakness allows attackers to bypass origin checks for absolute URLs and wildcard domains. By crafting a malicious 'callbackURL' parameter, an attacker can coerce the application into redirecting users to an attacker-controlled domain. This redirection is typically used to facilitate phishing campaigns or to intercept authentication tokens during the OAuth flow, eventually leading to account takeover. The vulnerability highlights a critical failure in the validation of redirect destinations, which is a common vector for credential and session token theft in modern web applications.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target web application utilizing an outdated version of better-auth (below 1.1.20).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious URL containing a crafted 'callbackURL' parameter designed to bypass the 'trustedOrigins' whitelist.\u003c/li\u003e\n\u003cli\u003eAttacker distributes the link to an authenticated user via phishing, social engineering, or a malicious third-party site.\u003c/li\u003e\n\u003cli\u003eThe victim clicks the link, initiating a legitimate request to the vulnerable application.\u003c/li\u003e\n\u003cli\u003eThe application's server-side logic fails to validate the 'callbackURL' properly due to the flaw in the 'trustedOrigins' implementation.\u003c/li\u003e\n\u003cli\u003eThe application performs an HTTP 302 redirect, sending the victim's browser, along with any sensitive session or authentication tokens, to the attacker-controlled destination.\u003c/li\u003e\n\u003cli\u003eAttacker captures the tokens from the referral header or URL parameters on the malicious site.\u003c/li\u003e\n\u003cli\u003eAttacker uses the stolen tokens to impersonate the victim and perform an account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the potential theft of authentication tokens, granting attackers unauthorized access to user accounts. This impacts any web application integrating better-auth for authentication flows. While the number of affected organizations is broad, the impact is localized to users of the specific web applications that have not yet updated to version 1.1.20 or later. Unauthorized access can result in data exfiltration, service disruption, and loss of user trust.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade better-auth to version 1.1.20 or higher immediately to resolve the vulnerable 'trustedOrigins' validation logic as specified in CVE-2025-71403.\u003c/li\u003e\n\u003cli\u003eAudit application logs for abnormal redirect patterns or high frequencies of requests to uncommon domains originating from authentication callback endpoints.\u003c/li\u003e\n\u003cli\u003eImplement strict Content Security Policy (CSP) headers to restrict where the browser is permitted to navigate during authentication redirects.\u003c/li\u003e\n\u003cli\u003eReview and harden all redirect validation logic across the web application, ensuring that only expected, pre-validated domains are accepted in callback parameters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-01T13:51:33Z","date_published":"2026-08-01T13:51:33Z","id":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-bypass/","summary":"The better-auth library contains a vulnerability in its trustedOrigins validation logic that allows attackers to perform open redirects and steal sensitive tokens by manipulating the callbackURL parameter.","title":"Open Redirect Vulnerability in better-auth via trustedOrigins Bypass","url":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Better-Auth (\u003c 1.1.20)","version":"https://jsonfeed.org/version/1.1"}