CVE-2025-71404
Last modified
CVE-2025-71404 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScript in the context of the user's browser. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScript in the context of the user's browser. The issue is fixed in version 1.1.16.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| better-auth | better-auth | < 1.1.16 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-71404?
How severe is CVE-2025-71404?
How do I fix CVE-2025-71404?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-71399Better Auth relies on better-call, which uses the rou3 route…8.6
- CVE-2025-7140A vulnerability classified as problematic has been found in …5.4
- CVE-2025-71400better-auth passkey versions before 1.4.0 contain an insecur…7.1
- CVE-2025-71401better-auth (npm) before 1.4.2 allows an external request to…5.9
- CVE-2025-71402better-auth versions greater than 1.3.34 and before 1.4.0 co…2
- CVE-2025-71403better-auth versions before 1.1.20 contain a bypass vulnerab…7.1
- CVE-2025-71405chi versions before v5.2.2 contain an open redirect vulnerab…5.1
- CVE-2025-71406Rejected reason: This CVE ID has been rejected as a duplicat…
- CVE-2025-71407Rejected reason: This CVE ID has been rejected as a duplicat…
- CVE-2025-71408NLTK (Natural Language Toolkit) before version 3.9.3 contain…8.5
- CVE-2025-71409Lack of authentication for Very High Frequency Data Link mes…7.1
- CVE-2025-7141A vulnerability classified as problematic was found in Sourc…5.4
Are you affected by CVE-2025-71404?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
