Skip to content

[GHSA-569q-mpph-wgww] Better Auth affected by external request basePath modification DoS - #8942

Closed
FROWNINGdev wants to merge 1 commit into
FROWNINGdev/advisory-improvement-8942from
FROWNINGdev-GHSA-569q-mpph-wgww
Closed

[GHSA-569q-mpph-wgww] Better Auth affected by external request basePath modification DoS#8942
FROWNINGdev wants to merge 1 commit into
FROWNINGdev/advisory-improvement-8942from
FROWNINGdev-GHSA-569q-mpph-wgww

Conversation

@FROWNINGdev

Copy link
Copy Markdown

Updates

  • CVSS v4
  • Severity

Comments
Note: I did not intend to change the CVSS score. The stored vector ends with the CVSS 4.0 Threat metric /E:P, which this form's calculator rejects ("vector string contains an error"); I dropped only that suffix so the form would validate. The Base metrics are unchanged.

@github

github commented Aug 2, 2026

Copy link
Copy Markdown
Collaborator

Hi there @Bekacru! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions
github-actions Bot changed the base branch from main to FROWNINGdev/advisory-improvement-8942 August 2, 2026 17:09
@FROWNINGdev

Copy link
Copy Markdown
Author

Apologies — this PR does not reflect what I intended to submit, and I'd suggest not merging it as-is.
The CVSS change is unintended. The form's calculator rejected the stored vector with "The entered vector string contains an error" because it ends with the CVSS 4.0 Threat metric /E:P, which the widget does not parse. Dropping that suffix was the only way to get the form to validate — it was not a judgement about the score, and the resulting LOW → MODERATE bump is an artifact of losing the Threat metric. Please revert both the vector and the severity.
What I actually wanted to contribute: this advisory has no CVE ID, while GHSA-3q45-2fh7-66cj (unreviewed) describes the same vulnerability — better-auth basePath poisoning DoS via an unconfigured baseURL, fixed in 1.4.2 — under CVE-2025-71401, and cites this advisory as its upstream source. The two records are duplicates of a single issue, split across keys: this one carries the package mapping (npm:better-auth, < 1.4.2) but no CVE, the other carries the CVE but no package mapping. Consumers matching on CVE therefore miss the affected-version data, and Dependabot-style matching on the package misses the CVE.

The form appears to reject the alias because the CVE is already held by the unreviewed record, so this likely needs a curator-side merge rather than a form submission.

@FROWNINGdev

Copy link
Copy Markdown
Author

Closing this in favour of #8943, which contains only the change I actually intended: adding CVE-2025-71401 to aliases, with the CVSS vector and severity left untouched. Sorry for the noise.

@FROWNINGdev FROWNINGdev closed this Aug 2, 2026
@github-actions
github-actions Bot deleted the FROWNINGdev-GHSA-569q-mpph-wgww branch August 2, 2026 17:19
FROWNINGdev added a commit to FROWNINGdev/advisory-database that referenced this pull request Aug 2, 2026
The previous submission for this advisory (github#8942) was
still open when this PR was created, so the check failed with "You already have
a pending improvement for this advisory". github#8942 is now closed; this empty commit
re-triggers the check. No file changes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants