better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScript in the context of the user's browser. The issue is fixed in version 1.1.16.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 01 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Better-auth better Auth
|
|
| Vendors & Products |
Better-auth better Auth
|
Sat, 01 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScript in the context of the user's browser. The issue is fixed in version 1.1.16. | |
| Title | better-auth before 1.1.16 Reflected XSS via error parameter | |
| First Time appeared |
Better-auth
Better-auth better-auth\/oauth-provider |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:better-auth:better-auth\/oauth-provider:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Better-auth
Better-auth better-auth\/oauth-provider |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-01T12:22:17.885Z
Reserved: 2026-07-18T12:38:41.077Z
Link: CVE-2025-71404
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-01T14:15:03Z
Weaknesses