Intel

AIKIDO-2025-10118

better-auth is vulnerable to Open Redirect

Open Redirect Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 27, 2025

90

Critical Risk

This Affects:

JSbetter-auth
0.6.2 - 1.1.20
Fixed in 1.1.21
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an open redirect due to insufficient validation of the callbackURL parameter in the trustedOrigins configuration. Attackers can exploit this by crafting specially formatted URLs that bypass trustedOrigins protection, potentially redirecting users to malicious sites.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

better-auth is vulnerable to Open Redirect in versions 0.6.2 - 1.1.20.

How to fix this

Upgrade the better-auth library to the patch version.