Impact
An attacker who can execute commands locally can manipulate the icons_file argument supplied to the scan_project_icons/sync_icon feature of better-auth better-icons, causing the application to resolve filesystem paths outside the intended icons directory. This classic path‑traversal flaw can allow the reader to access arbitrary files on the host. The vulnerability is identified as CWE‑22, involving improper handling of relative paths.
Affected Systems
The flaw exists in better-auth better-icons releases up to and including version 1.0.5, and in all earlier releases that contain the scan_project_icons/sync_icon component. No patch or update has been published to remove the issue, so any deployment of these versions remains vulnerable.
Risk and Exploitability
The CVSS score is 4.8 and the EPSS score is reported as less than 1 %, indicating a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires local access, it can be exploited only by an adversary who already has code execution or sufficient privileges on the system. Once privilege is gained, the path traversal could expose critical configuration or sensitive files, and depending on how sync_icon writes data, it could also allow modification of those files.
OpenCVE Enrichment