CyberRota Analysis
AI-GeneratedAn external request can manipulate the baseURL configuration in better-auth (npm) versions prior to 1.4.2, leading to a denial of service by causing all routes to return 404 errors. This vulnerability primarily affects deployments where the BETTER_AUTH_URL is unset and the server has just started, making it critical for developers and system administrators using this package to prioritize patching or configuring the baseURL explicitly. Users on managed hosting platforms or those with a defined baseURL are not impacted.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to return 404 for all users (denial of service). The issue is not reachable when baseURL is explicitly configured or on typical managed hosting platforms.