Executive brief
Better Auth is a comprehensive authentication framework used to manage user login and identity flows. An issue in its underlying router allows attackers to bypass security controls by using double-slash URLs (e.g., //sign-in/email instead of /sign-in/email), potentially circumventing disabled path restrictions and rate-limiting protections that are meant to prevent abuse.
Technical details
The vulnerability exists in the rou3 router library, which Better Auth uses via the better-call dependency. The affected versions of rou3 normalize URL paths by removing empty segments, causing /path, //path, and ///path to resolve to identical routes. If the network infrastructure does not normalize multiple slashes before reaching Better Auth (e.g., in environments without Vercel/Next.js or Cloudflare URL normalization enabled), an attacker can craft requests with double-slash paths to bypass path-based disabledPaths configuration and rate-limiting controls. The attack requires no authentication and can be exploited remotely over the network. The fix was introduced in rou3 after version 0.5.1; Better Auth v1.4.5 and later include the patched dependency.
Affected products
- Better Auth Better Auth < 1.4.5
Timeline
- 2025-12-16: disclosed
- 2025-12-16: patched: Better Auth v1.4.5 or later includes patched rou3