CVE-2025-61928Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ?? (authRequired ? null : { id: ctx.body.userId })`. When no session exists but `userId` is present in the request body, `authRequired` becomes false and the user object is set to the attacker-controlled ID. Server-only field validation only executes when `authRequired` is true (lines 280-295), allowing attackers to set privileged fields. No additional authentication occurs before the database operation, so the malicious payload is accepted. The same pattern exists in the update endpoint. This is a critical authentication bypass enabling full an unauthenticated attacker can generate an API key for any user and immediately gain complete authenticated access. This allows the attacker to perform any action as the victim user using the api key, potentially compromise the user data and the application depending on the victim's privileges. Version 1.3.26 contains a patch for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-18); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-18: 1Mentions · 2026-02-19: 1Mentions · 2026-03-28: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-03-28: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-28: 102-1802-1903-28
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-181
Disclosure1
2026-02-191
Disclosure1
2026-03-281
Patch1
Full discourse3 posts
  • reverseame@reverseame
    Disclosure

    Critical Account Takeover via Unauthenticated API Key Creation in better-auth (CVE-2025-61928) #AccountTakeover #BetterAuth #CVE202561928 #APIKeySecurity #ZeroPath https://zeropath.com/blog/breaking-authentication-unauthenticated-api-key-creation-in-better-auth-cve-2025-61928

    Post summary

    The tweet announces CVE‑2025‑61928, a critical account takeover vulnerability in better‑auth caused by unauthenticated API key creation, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00086807
    21.6K followersView on X
  • Jed Frankowski@JedFrankowski
    Patch

    Better-Auth is self-hosted - it stores users, sessions & auth data in your own database. → One DB breach = full auth exposure. → Already had critical CVE-2025-61928 (unauth API key takeover + MFA bypass). You’d have to patch it yourself. Do you have time for that? Auth is too critical to beta-test. Prefer proven managed services like Auth0, Cognito, or Clerk.

    Post summary

    The post highlights a critical vulnerability (CVE-2025-61928) in the self‑hosted Better‑Auth platform, noting unauthenticated API key takeover and MFA bypass, and warns users must manually apply a patch.

    20002814
    307 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 CVE-2025-61928: better-auth API Keys Plugin Lets Attackers Mint Privileged Keys Without Logging In A logic flaw in better-auth’s `createApiKey` (and `updateApiKey`) handler allows unauthenticated requests that include a `userId` to bypass auth checks and generate valid API keys for arbitrary accounts—potentially with privileged fields like permissions and rate limits. Upgrade to 1.3.26+ and rotate keys; hunt for unauthenticated POSTs to `/api/auth/api-key/create` or `/api/auth/api-key/update` with `userId` in the body. 🎯 Target: Global/Developers (Node.js apps using better-auth) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/authentication-bypass-better-auth-api-keys/

    Post summary

    A logic flaw in better‑auth’s API key handling lets attackers mint privileged keys without authentication; the issue is disclosed with an advisory to upgrade to 1.3.26+ and rotate keys.

    0000033
    174 followersView on X

Explore more