CVE-2025-71404EPSS p42.2%
CVE-2025-71404CVE-2025-71404
Description
better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScript in the context of the user's browser. The issue is fixed in version 1.1.16.
Scoring
| EPSS | 0.52% probability of exploitation · percentile 42.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-29 |