better-auth Vulnerabilities and Affected Products
Vulnerabilities associated with passkey.
Products
Clear product- better-auth25 vulnerabilities
- oauth-provider2 vulnerabilities
- scim2 vulnerabilities
- better-icons1 vulnerability
- passkey1 vulnerability
- sso1 vulnerability
- stripe1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-71400HIGH | better-auth passkey before 1.4.0 IDOR via delete-passkeybetter-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys. CWE-639Aug 2, 2026 | CVSS7.1v4.0 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |