AI description
CVE-2025-71400 describes an Insecure Direct Object Reference (IDOR) vulnerability found in `better-auth passkey` versions prior to 1.4.0. This flaw specifically affects the passkey deletion endpoint within the software. The vulnerability enables authenticated users to delete arbitrary passkeys by their ID. An attacker with a valid session can craft and submit requests to the `delete-passkey` endpoint, allowing them to remove other users' passkeys by enumerating their IDs.
- Description
- better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys.
- Source
- disclosure@vulncheck.com
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 7.1
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Secondary
- Base score
- 7.1
- Impact score
- 4.2
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
- Severity
- HIGH
- disclosure@vulncheck.com
- CWE-639
- Hype score
- Not currently trending
🚨*CVE* CVE-2025-71400 better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users t… https://t.co/XoUWEBEs7M ----- Traducción: CVE-2025-71400 bet… https://t.co/utmtNg
@infoflowcloud
2 Aug 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-71400 better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users t… https://t.co/HSJeIpUkfz
@CVEnew
2 Aug 2026
1073 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-71400 Insecure Direct Object Reference in better-auth Passkey Deletion ... https://t.co/DyQOUOvacO Vulnerability Alert Subscriptions: https://t.co/hrQhy5uz4x
@VulmonFeeds
2 Aug 2026
140 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes