{"id":"CVE-2025-71404","aliases":["GHSA-9x4v-xfq5-m8x5"],"url":"https://o3.security/vulnerability/CVE-2025-71404","summary":"better-auth before 1.1.16 Reflected XSS via error parameter","details":"better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScript in the context of the user's browser. The issue is fixed in version 1.1.16.","published":"2026-08-01T12:22:17.885Z","modified":"2026-09-10T03:30:18.440385810Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"better-auth","fixedVersion":"1.1.16"}],"fix":{"url":"https://github.com/better-auth/better-auth/commit/05ada0b79dbcac93cc04ceb79b23ca598d07830c","label":"better-auth/better-auth@05ada0b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71404.json"},{"type":"ADVISORY","url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-9x4v-xfq5-m8x5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71404"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/better-auth-before-reflected-xss-via-error-parameter"},{"type":"FIX","url":"https://github.com/better-auth/better-auth/commit/05ada0b79dbcac93cc04ceb79b23ca598d07830c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:30:18.440385810Z"}}