GitHub Security Advisory (GHSA-4vcf-q4xf-f48m)Vendor advisory
https://github.com/better-auth/better-auth/security/advisories/GHSA-4vcf-q4xf-f48m CVE-2025-71400
HIGH
better-auth passkey before 1.4.0 IDOR via delete-passkey
Record summary
CVE-2025-71400 has a selected CVSS score of 7.1 (high).
Description
better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
passkeyBrowse better-auth / passkeyDefault status: unaffected | CVE List | Before 1.4.0 | affected |
| 1.4.0 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-71400 VulnCheck Advisory: better-auth passkey before 1.4.0 IDOR via delete-passkeyThird-party advisory
https://www.vulncheck.com/advisories/better-auth-passkey-before-idor-via-delete-passkey