Vulnerability Description
Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-link/verify, /oauth-proxy-callback. This vulnerability is fixed in 1.2.10.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-53535?
CVE-2025-53535 is a documented vulnerability. Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /r...
How severe is CVE-2025-53535?
CVSS scoring is not yet available for CVE-2025-53535. Check NVD for updates.
Is there a patch for CVE-2025-53535?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.