{"id":"CVE-2025-71400","aliases":["GHSA-4vcf-q4xf-f48m"],"url":"https://o3.security/vulnerability/CVE-2025-71400","summary":"better-auth passkey before 1.4.0 IDOR via delete-passkey","details":"# Summary\n\nAffected versions of the better-auth passkey plugin allow users with any valid session to delete arbitrary passkeys via their ID using `POST /passkey/delete-passkey`.\n\n# Details\n\n`ctx.body.id` is implicitly trusted and used in passkey deletion queries.\n\nbetter-auth applications configured with `useNumberId` may use auto incrementing IDs which makes it trivial to delete all passkeys via enumeration.","published":"2026-08-02T12:15:22.830Z","modified":"2026-09-10T03:30:34.879396539Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@better-auth/passkey","fixedVersion":"1.4.0"}],"fix":{"url":"https://github.com/better-auth/better-auth/commit/06d68239e","label":"better-auth/better-auth@06d6823"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71400.json"},{"type":"ADVISORY","url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-4vcf-q4xf-f48m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71400"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/better-auth-passkey-before-idor-via-delete-passkey"},{"type":"WEB","url":"https://github.com/better-auth/better-auth/commit/06d68239e"},{"type":"PACKAGE","url":"https://github.com/better-auth/better-auth"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:30:34.879396539Z"}}