GitHub Security Advisory (GHSA-wmjr-v86c-m9jj)Vendor advisory
https://github.com/better-auth/better-auth/security/advisories/GHSA-wmjr-v86c-m9jj CVE-2025-71402
LOW
better-auth before 1.4.0 Session Revocation via Forged Cookie
Record summary
CVE-2025-71402 has a selected CVSS score of 2.0 (low).
Description
better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions without verifying the cookie signature (e.g., via getSignedCookie). An attacker can supply a forged _multi-* cookie to trigger deletion of arbitrary session tokens.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
better-authBrowse better-auth / better-authDefault status: unaffected | CVE List | Before 1.4.0 | affected |
| 1.4.0 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-71402 VulnCheck Advisory: better-auth before 1.4.0 Session Revocation via Forged CookieThird-party advisory
https://www.vulncheck.com/advisories/better-auth-before-session-revocation-via-forged-cookie