ADK Cyber[verified]@ADKCyberDisclosure
High‑severity CVE‑2025‑71401 impacts better‑auth npm <1.4.2 when baseURL is unset; CVSS 9.3, and users are advised to update dependencies promptly.
CVE@CVEnewDisclosure
The post discloses that CVE‑2025‑71401 in better‑auth <=1.4.1 allows an external request to set baseURL when unset, exposing a potential security flaw.
Infoflowcloud@infoflowcloudGeneral
A brief technical description of CVE‑2025‑71401 is provided, noting a flaw in the better‑auth npm package that allows external configuration of baseURL when not predefined; no evidence of exploits, patches, or PoCs is included.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2025-71401 is a denial‑of‑service vulnerability in better‑auth <1.4.2 caused by base‑URL configuration poisoning, as stated in the disclosure.