Executive brief
Better Auth is an authentication library used to implement email verification and user login flows in web applications. An attacker can craft malicious email verification links that redirect users to attacker-controlled websites after email verification succeeds, enabling phishing attacks, credential theft, and account takeover through stolen authentication tokens.
Technical details
Better Auth's email verification endpoint (/auth/verify-email) and other callback-accepting endpoints contain an open redirect vulnerability (CWE-601) due to improper URL validation. The application blocks fully qualified external URLs (e.g., https://evil.com) but fails to prevent scheme-less URLs (e.g., //malicious-site.com), which browsers interpret as protocol-relative URLs and redirect to the attacker's domain over HTTPS. An unauthenticated attacker can exploit this by embedding a malicious callbackURL parameter in a crafted verification link; when a user clicks the link and verifies their email, they are automatically redirected to the attacker's site. This affects all versions prior to 1.1.20 and is patched in v1.1.21.
Affected products
- Better Auth Better Auth prior to 1.1.20
Timeline
- 2025-02-24: disclosed: Published as GHSA-hjpm-7mrm-26w8
- 2025-02-24: patched: Fixed in version 1.1.20 and 1.1.21