Better Auth has an Open Redirect Vulnerability in originCheck Middleware Affecting Multiple Routes
Vulnerability Description
Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-link/verify, /oauth-proxy-callback. This vulnerability is fixed in 1.2.10.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53535
Credits & Attribution
No credits recorded in the NVD database.
More from better-auth
View All →Affected Vendor
better-auth
View all reports →