<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T00:01:07.310337+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-246549</id>
    <title>EUVD-2026-246549</title>
    <updated>2026-10-10T00:01:07.363579+00:00</updated>
    <content>EUVD-2026-246549</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-246549"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53535</id>
    <title>fkie_cve-2025-53535</title>
    <updated>2026-10-10T00:01:07.363616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-link/verify, /oauth-proxy-callback. This vulnerability is fixed in 1.2.10.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-53535"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-36rg-gfq2-3h56</id>
    <title>GHSA-36rg-gfq2-3h56 — Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes</title>
    <updated>2026-10-10T00:01:07.363651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: better-auth</p>
<p>### Summary</p>
<p>An open redirect has been found in the `originCheck` middleware function, which affects the following routes: `/verify-email`, `/reset-password/:token`, `/delete-user/callback`, `/magic-link/verify`, `/oauth-proxy-callback`.</p>
<p>### Details</p>
<p>In the `matchesPattern` function, `url.startsWith(` can be deceived with a `url` that starts with one of the `trustedOrigins`.</p>
<p>```jsx
		const matchesPattern = (url: string, pattern: string): boolean =&gt; {
			if (url.startsWith("/")) {
				return false;
			}
			if (pattern.includes("*")) {
				return wildcardMatch(pattern)(getHost(url));
			}
			return url.startsWith(pattern);
		};
```</p>
<p>### Open Redirect PoCs</p>
<p>```jsx
export const auth = betterAuth({
	baseURL: 'http://localhost:3000',
	trustedOrigins: [
		"http://trusted.com"
	],
	emailAndPassword: {
		...
	},
})
```</p>
<p>#### `/reset-password/:token`</p>
<p>&lt;img width="481" alt="image" src="https://github.com/user-attachments/assets/46e7871a-1dad-4375-af94-0446e29aaab6" /&gt;
&lt;br/&gt;
&lt;img width="518" alt="image 1" src="https://github.com/user-attachments/assets/83abfb53-6fc9-4d1f-918d-9b4ce093c808" /&gt;</p>
<p>#### `/verify-email`</p>
<p>&lt;img width="549" alt="image" src="https://github.com/user-attachments/assets/7dd424b7-42a4-4616-aa73-fcc2e3eeb309" /&gt;
&lt;br/&gt;
&lt;img width="436" alt="image" src="https://github.com/user-attachments/assets/54f11636-0a3e-4e83-9a09-57c5e8ba98cd" /&gt;</p>
<p>#### `/delete-user/callback`</p>
<p>&lt;img width="545" alt="image" src="https://github.com/user-attachments/assets/2ff1b217-d069-48fb-81c1-f8…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-36rg-gfq2-3h56"/>
  </entry>
</feed>
