Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
High severity
GitHub Reviewed
Published
Feb 24, 2025
in
better-auth/better-auth
•
Updated Dec 9, 2025
Description
Published to the GitHub Advisory Database
Feb 24, 2025
Reviewed
Feb 24, 2025
Last updated
Dec 9, 2025
Summary
A bypass was discovered in the trustedOrigins validation logic—affecting both absolute URL entries and wildcard domain patterns. This flaw allows an attacker to construct a malicious callbackURL that passes origin checks and triggers an open redirect.
Because redirect endpoints include sensitive tokens (such as password-reset tokens), this vulnerability can enable one-click account takeover if a victim clicks a crafted link.
References