THREAT OPS › Threat News › [NVD] CVE-2025-71404 — better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visit
[NVD] CVE-2025-71404 — better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visit
CVE-2025-71404 CVSS: None Published: 2026-08-01T13:16:56.777
better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScr
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2025-71404cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-71404