{"id":"GHSA-vp58-j275-797x","summary":"Better Auth allows bypassing the trustedOrigins Protection which leads to ATO","details":"### Summary\n\nA bypass was discovered in the trustedOrigins validation logic—affecting both absolute URL entries and wildcard domain patterns. This flaw allows an attacker to construct a malicious callbackURL that passes origin checks and triggers an open redirect.\n\nBecause redirect endpoints include sensitive tokens (such as password-reset tokens), this vulnerability can enable one-click account takeover if a victim clicks a crafted link.","aliases":["CVE-2025-71403"],"modified":"2026-08-02T03:56:47.282836883Z","published":"2025-02-24T20:49:50Z","database_specific":{"github_reviewed_at":"2025-02-24T20:49:50Z","nvd_published_at":null,"cwe_ids":["CWE-601"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-vp58-j275-797x"},{"type":"WEB","url":"https://github.com/better-auth/better-auth/commit/b381cac7aafd6aa53ef78b6ab771ebfa24643c80"},{"type":"PACKAGE","url":"https://github.com/better-auth/better-auth"},{"type":"WEB","url":"https://github.com/better-auth/better-auth/blob/ddebd0358d74376ea64541512d0167dd4377f182/packages/better-auth/src/api/middlewares/origin-check.ts#L53"}],"affected":[{"package":{"name":"better-auth","ecosystem":"npm","purl":"pkg:npm/better-auth"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.21"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.1.20","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-vp58-j275-797x/GHSA-vp58-j275-797x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"}]}