Executive brief
Better Auth is an authentication library used by web applications to manage user sessions. The library's multi-session sign-out feature fails to validate cookie signatures, allowing an attacker to forge session cookies and force the sign-out of other users' sessions. This could disrupt service for legitimate users or be chained with other attacks to facilitate account compromise.
Technical details
The vulnerability is an authentication bypass in the multi-session plugin's /sign-out after-hook. The hook extracts values from raw _multi-* cookies and passes them directly to internalAdapter.deleteSessions without validating the cookie signature using getSignedCookie or equivalent verification. An attacker on the network can craft forged cookies to trigger deletion of arbitrary session tokens. The issue affects Better Auth versions 1.3.34 through 1.3.x and is fixed in version 1.4.0. The attack requires network access and high privileges but only passive user interaction, resulting in low confidentiality, integrity, and availability impact according to CVSS v4.
Affected products
- Better Auth better-auth 1.3.34 through 1.3.x, fixed in 1.4.0
Timeline
- 2025-11-26: disclosed
- 2025-11-26: patched: Version 1.4.0 available as of disclosure date