Settings

Theme

Better-auth account takeover (CVE-2025-61928) found via ZeroPath

zeropath.com

9 points by etlun 2 months ago · 4 comments

Reader

etlunOP 2 months ago

Author here, we found it while building & documenting automated dependency assessment workflows for ZeroPath recently. Better-Auth made for a good test case given its popularity (300K weekly downloads).

The vulnerability is a logic error in how the API keys plugin determines user context when a userId is specified. Fix is in version 1.3.26. This is the kind of business logic flaw that traditional dependency vetting (stars, existing CVEs, reputation) doesn't catch. We're working on tooling to make these audits more practical at scale.

rkusr 2 months ago

Interesting, wonder how long this has been latent for

subbaiks 2 months ago

this is actually insane how far AI SAST like ZeroPath and others have come

adarsharma 2 months ago

this is actually so cool

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection