CVE-2025-27143 - CVE House
Back to Database
Status published Medium CVE-2025-27143

Beter Auth has an Open Redirect via Scheme-Less Callback Parameter

Vulnerability Description

Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect due to improper validation of the callbackURL parameter in the email verification endpoint and any other endpoint that accepts callback url. While the server blocks fully qualified URLs, it incorrectly allows scheme-less URLs. This results in the browser interpreting the URL as a fully qualified URL, leading to unintended redirection. An attacker can exploit this flaw by crafting a malicious verification link and tricking users into clicking it. Upon successful email verification, the user will be automatically redirected to the attacker's website, which can be used for phishing, malware distribution, or stealing sensitive authentication tokens. This CVE is a bypass of the fix for GHSA-8jhw-6pjj-8723/CVE-2024-56734. Version 1.1.21 contains an updated patch.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27143

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

better-auth

View all reports →

Affected Software

better-auth
Vulnerable Versions:
< 1.1.20

Timeline

Official Publish: February 24th, 2025
Last Modified: February 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)