Impact
The vulnerability in better-auth versions prior to 1.4.9 allows an attacker who already possesses valid primary credentials to gain access to routes that normally require second‑factor verification. This occurs when the session.cookieCache feature is enabled, which caches session authentication prematurely, effectively skipping the second‑factor step for subsequent requests.
Affected Systems
better-auth, the <better-auth:better-auth> OAuth provider, is affected in all releases older than 1.4.9. Users running a version before 1.4.9 that has session cookie caching enabled are vulnerable.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability presents a moderate to high severity risk. The exploit requires the attacker to first obtain legitimate primary credentials, which could be achieved via phishing, credential stuffing, or other standard credential‑based attacks. Although a precise EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, the combination of a high CVSS score and the ease of obtaining primary credentials suggests that exploitation is plausible if not frequently observed. Immediate remediation is advised to prevent unauthorized access to protected resources.
OpenCVE Enrichment