better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). (CVE-2025-71401)
better-auth (npm) versions before 1.4.2 have a vulnerability where an external request can set the baseURL if it is not predefined (e.g., BETTER_AUTH_URL unset). This allows an attacker making the first request after server startup to poison the router's base path, causing all routes to return 404 errors and resulting in denial of service for all users. The vulnerability is not exploitable if baseURL is explicitly configured or on typical managed hosting platforms.
AI Analysis
Technical Summary
The better-auth npm package prior to version 1.4.2 permits an external request to configure the baseURL when it is not otherwise defined, such as when the BETTER_AUTH_URL environment variable is unset. An attacker who can make the very first request to the server after it starts can manipulate the router's base path, causing all subsequent route requests to fail with 404 errors. This results in a denial of service condition affecting all users. The issue is mitigated if baseURL is explicitly set or when deployed on managed hosting platforms that define this configuration.
Potential Impact
This vulnerability leads to a denial of service by poisoning the router's base path, causing all routes to return 404 errors for all users. There is no confidentiality or integrity impact reported. The attack requires the ability to make the first request after server startup and is not exploitable if baseURL is explicitly configured or on typical managed hosting environments.
Mitigation Recommendations
Upgrade better-auth to version 1.4.2 or later where this issue is fixed. If upgrading is not immediately possible, ensure that the baseURL is explicitly configured (e.g., set BETTER_AUTH_URL) to prevent external requests from setting it. Typical managed hosting platforms that define baseURL are not affected. Patch status is not explicitly confirmed in the provided data; verify the vendor advisory for current remediation guidance.
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). (CVE-2025-71401)
Description
better-auth (npm) versions before 1.4.2 have a vulnerability where an external request can set the baseURL if it is not predefined (e.g., BETTER_AUTH_URL unset). This allows an attacker making the first request after server startup to poison the router's base path, causing all routes to return 404 errors and resulting in denial of service for all users. The vulnerability is not exploitable if baseURL is explicitly configured or on typical managed hosting platforms.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The better-auth npm package prior to version 1.4.2 permits an external request to configure the baseURL when it is not otherwise defined, such as when the BETTER_AUTH_URL environment variable is unset. An attacker who can make the very first request to the server after it starts can manipulate the router's base path, causing all subsequent route requests to fail with 404 errors. This results in a denial of service condition affecting all users. The issue is mitigated if baseURL is explicitly set or when deployed on managed hosting platforms that define this configuration.
Potential Impact
This vulnerability leads to a denial of service by poisoning the router's base path, causing all routes to return 404 errors for all users. There is no confidentiality or integrity impact reported. The attack requires the ability to make the first request after server startup and is not exploitable if baseURL is explicitly configured or on typical managed hosting environments.
Mitigation Recommendations
Upgrade better-auth to version 1.4.2 or later where this issue is fixed. If upgrading is not immediately possible, ensure that the baseURL is explicitly configured (e.g., set BETTER_AUTH_URL) to prevent external requests from setting it. Typical managed hosting platforms that define baseURL are not affected. Patch status is not explicitly confirmed in the provided data; verify the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3q45-2fh7-66cj
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-71401"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a6fb62cbf32cb7a346e720a
Added to database: 08/02/2026, 21:27:08 UTC
Last enriched: 08/02/2026, 21:29:16 UTC
Last updated: 09/15/2026, 22:09:01 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.