CVE-2025-71401Disclosure

LOW

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-02: 4Patch / Workaround · 2026-08-02: 1Technical Details · 2026-08-02: 408-02
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-71401 better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to … https://www.cve.org/CVERecord?id=CVE-2025-71401

    Post summary

    The post discloses that CVE‑2025‑71401 in better‑auth <=1.4.1 allows an external request to set baseURL when unset, exposing a potential security flaw.

    00010991
    57.9K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    High-severity CVE-2025-71401 (CVSS 9.3) affects better-auth npm &lt;1.4.2 when baseURL is unset. Review and update dependencies promptly. https://nvd.nist.gov/vuln/detail/CVE-2025-71401 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/0hrABleEZI

    Post summary

    High‑severity CVE‑2025‑71401 impacts better‑auth npm <1.4.2 when baseURL is unset; CVSS 9.3, and users are advised to update dependencies promptly.

    0000069
    90 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2025-71401 better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to … https://www.cve.org/CVERecord?id=CVE-2025-71401 ----- Traducción: CVE-2025-71401 bet… http://infoflow.cloud`

    Post summary

    A brief technical description of CVE‑2025‑71401 is provided, noting a flaw in the better‑auth npm package that allows external configuration of baseURL when not predefined; no evidence of exploits, patches, or PoCs is included.

    0000030
    96 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-71401 Denial of Service via Base URL Configuration Poisoning in better-auth Before 1.4.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-71401

    Post summary

    CVE-2025-71401 is a denial‑of‑service vulnerability in better‑auth <1.4.2 caused by base‑URL configuration poisoning, as stated in the disclosure.

    00000122
    4.1K followersView on X

Explore more