<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 03:26:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-246549</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-246549</link>
      <description>EUVD-2026-246549</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-246549</guid>
    </item>
    <item>
      <title>fkie_cve-2025-53535</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53535</link>
      <description>&lt;p&gt;Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-link/verify, /oauth-proxy-callback. This vulnerability is fixed in 1.2.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-link/verify, /oauth-proxy-callback. This vulnerability is fixed in 1.2.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-53535</guid>
    </item>
    <item>
      <title>GHSA-36rg-gfq2-3h56 — Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-36rg-gfq2-3h56</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: better-auth&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An open redirect has been found in the `originCheck` middleware function, which affects the following routes: `/verify-email`, `/reset-password/:token`, `/delete-user/callback`, `/magic-link/verify`, `/oauth-proxy-callback`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In the `matchesPattern` function, `url.startsWith(` can be deceived with a `url` that starts with one of the `trustedOrigins`.&lt;/p&gt;
&lt;p&gt;```jsx
		const matchesPattern = (url: string, pattern: string): boolean =&amp;gt; {
			if (url.startsWith(&amp;#34;/&amp;#34;)) {
				return false;
			}
			if (pattern.includes(&amp;#34;*&amp;#34;)) {
				return wildcardMatch(pattern)(getHost(url));
			}
			return url.startsWith(pattern);
		};
```&lt;/p&gt;
&lt;p&gt;### Open Redirect PoCs&lt;/p&gt;
&lt;p&gt;```jsx
export const auth = betterAuth({
	baseURL: &amp;#39;http://localhost:3000&amp;#39;,
	trustedOrigins: [
		&amp;#34;http://trusted.com&amp;#34;
	],
	emailAndPassword: {
		...
	},
})
```&lt;/p&gt;
&lt;p&gt;#### `/reset-password/:token`&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;481&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/46e7871a-1dad-4375-af94-0446e29aaab6&amp;#34; /&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;img width=&amp;#34;518&amp;#34; alt=&amp;#34;image 1&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/83abfb53-6fc9-4d1f-918d-9b4ce093c808&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;#### `/verify-email`&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;549&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/7dd424b7-42a4-4616-aa73-fcc2e3eeb309&amp;#34; /&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;img width=&amp;#34;436&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/54f11636-0a3e-4e83-9a09-57c5e8ba98cd&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;#### `/delete-user/callback`&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;545&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/2ff1b217-d069-48fb-81c1-f8…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: better-auth&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An open redirect has been found in the `originCheck` middleware function, which affects the following routes: `/verify-email`, `/reset-password/:token`, `/delete-user/callback`, `/magic-link/verify`, `/oauth-proxy-callback`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In the `matchesPattern` function, `url.startsWith(` can be deceived with a `url` that starts with one of the `trustedOrigins`.&lt;/p&gt;
&lt;p&gt;```jsx
		const matchesPattern = (url: string, pattern: string): boolean =&amp;gt; {
			if (url.startsWith(&amp;#34;/&amp;#34;)) {
				return false;
			}
			if (pattern.includes(&amp;#34;*&amp;#34;)) {
				return wildcardMatch(pattern)(getHost(url));
			}
			return url.startsWith(pattern);
		};
```&lt;/p&gt;
&lt;p&gt;### Open Redirect PoCs&lt;/p&gt;
&lt;p&gt;```jsx
export const auth = betterAuth({
	baseURL: &amp;#39;http://localhost:3000&amp;#39;,
	trustedOrigins: [
		&amp;#34;http://trusted.com&amp;#34;
	],
	emailAndPassword: {
		...
	},
})
```&lt;/p&gt;
&lt;p&gt;#### `/reset-password/:token`&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;481&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/46e7871a-1dad-4375-af94-0446e29aaab6&amp;#34; /&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;img width=&amp;#34;518&amp;#34; alt=&amp;#34;image 1&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/83abfb53-6fc9-4d1f-918d-9b4ce093c808&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;#### `/verify-email`&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;549&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/7dd424b7-42a4-4616-aa73-fcc2e3eeb309&amp;#34; /&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;img width=&amp;#34;436&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/54f11636-0a3e-4e83-9a09-57c5e8ba98cd&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;#### `/delete-user/callback`&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;545&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/2ff1b217-d069-48fb-81c1-f8…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-36rg-gfq2-3h56</guid>
    </item>
  </channel>
</rss>
