Junglewise Threat Intelligence

CVE-2025-61928: Better Auth unauthenticated API key creation in api-key plugin

CVE-2025-61928 · Severity: low · CVSS 3.1 · Published 2025-10-09

Technologies: better-auth (npm). Vendors: npm, Better-Auth.

Executive brief

Better Auth is an open-source authentication library used to handle user login, registration, and API key management in web applications. A critical flaw in the API key plugin allows attackers to create or modify API keys for any user without authentication, effectively granting them complete account access and potentially exposing sensitive data or enabling account takeover.

Technical details

The vulnerability is an authentication bypass (CWE-285/CWE-306) in the API key creation and update endpoints. The root cause is fallback logic that incorrectly uses request-body data to populate the user context when no session is present, bypassing proper authorization checks. An unauthenticated attacker can supply an arbitrary user ID in the request body to generate or modify API keys for any target user. The flaw affects both API key creation and update routes and requires only network access (no authentication or user interaction). This grants the attacker full authenticated access under the compromised user's privileges, potentially enabling data breach or application compromise. The issue is fixed in version 1.3.26.

Affected products

  • Better Auth better-auth before 1.3.26

Timeline

  • 2025-10-09: disclosed
  • 2025-10-09: patched: Fixed in version 1.3.26

References

Related threats