better-auth is vulnerable to Open Redirect
90
Critical Risk
Affected versions of this package are vulnerable to an open redirect due to insufficient validation of the callbackURL parameter in the trustedOrigins configuration. Attackers can exploit this by crafting specially formatted URLs that bypass trustedOrigins protection, potentially redirecting users to malicious sites.
You are affected if you are using a version that falls within the vulnerable range.
better-auth is vulnerable to Open Redirect in versions 0.6.2 - 1.1.20.
Upgrade the better-auth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant