CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-71403

highCVSS 7.1covered by 1 sourcefirst seen 2026-08-01
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover.

⚡ Watch CVE-2025-71403

Get an email if CVE-2025-71403 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2025-71403

CVE.org record

Embed the live status

CVE-2025-71403 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-71403 status](https://www.csirts.com/badge/CVE-2025-71403)](https://www.csirts.com/cve/CVE-2025-71403)