Critical Authentication Bypass in better-auth API Keys Plugin Allows Unauthenticated Account Takeover

A critical authentication bypass vulnerability in the better-auth API keys plugin allows unauthenticated attackers to mint privileged API keys for arbitrary users. The flaw, tracked as CVE-2025-61928, affects all versions of the better-auth library prior to 1.3.26 — a package that sees approximately 300,000 weekly npm downloads and powers authentication for organizations ranging from startups […]

The post Critical Authentication Bypass in better-auth API Keys Plugin Allows Unauthenticated Account Takeover appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: