Skip to content

[GHSA-4vcf-q4xf-f48m] Better Auth Passkey plugin allows deletion of arbitrary passkeys by ID - #8944

Open
FROWNINGdev wants to merge 1 commit into
github:FROWNINGdev/advisory-improvement-8944from
FROWNINGdev:frowningdev-GHSA-4vcf-q4xf-f48m
Open

[GHSA-4vcf-q4xf-f48m] Better Auth Passkey plugin allows deletion of arbitrary passkeys by ID#8944
FROWNINGdev wants to merge 1 commit into
github:FROWNINGdev/advisory-improvement-8944from
FROWNINGdev:frowningdev-GHSA-4vcf-q4xf-f48m

Conversation

@FROWNINGdev

Copy link
Copy Markdown

Updates

  • Aliases (CVE ID)

Comments
Add CVE-2025-71400 as an alias for this advisory.

The unreviewed record GHSA-44ff-3cmc-mgqf describes the same vulnerability — an insecure direct object reference in the passkey deletion endpoint that lets an authenticated user delete other users' passkeys by enumerating IDs, fixed in 1.4.0 — and lists this advisory as its first reference. The two records are duplicates of a single issue, split across keys: this one carries the package mapping (npm:@better-auth/passkey, < 1.4.0) but no CVE ID, while the unreviewed record carries CVE-2025-71400 but no affected package or version data. Consumers matching on the CVE therefore miss the affected-version range, and consumers matching on the npm package miss the CVE.

This change is limited to the aliases field; no other fields are touched.

References

@github-actions
github-actions Bot changed the base branch from main to FROWNINGdev/advisory-improvement-8944 August 2, 2026 17:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant