
Critical Account Takeover via Unauthenticated API Key Creation in better-auth (CVE-2025-61928) #AccountTakeover #BetterAuth #CVE202561928 #APIKeySecurity #ZeroPath https://zeropath.com/blog/breaking-authentication-unauthenticated-api-key-creation-in-better-auth-cve-2025-61928
Post summary
The tweet announces CVE‑2025‑61928, a critical account takeover vulnerability in better‑auth caused by unauthenticated API key creation, but provides no PoC, exploit, patch, or evidence of active exploitation.


