CVE-2025-71404 | better-auth up to 1.1.15 Error Page /api/auth/error cross site scripting
A vulnerability was found in better-auth up to 1.1.15. It has been rated as problematic. The affected element is an unknown function of the file /api/auth/error of the component Error Page. The manipulation of the argument Error leads to cross site scripting.
This vulnerability is traded as CVE-2025-71404. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More