CVE-2025-71400

Published Aug 2, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-71400 describes an Insecure Direct Object Reference (IDOR) vulnerability found in `better-auth passkey` versions prior to 1.4.0. This flaw specifically affects the passkey deletion endpoint within the software. The vulnerability enables authenticated users to delete arbitrary passkeys by their ID. An attacker with a valid session can craft and submit requests to the `delete-passkey` endpoint, allowing them to remove other users' passkeys by enumerating their IDs.

Description
better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys.
Source
disclosure@vulncheck.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.1
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Secondary
Base score
7.1
Impact score
4.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Severity
HIGH

Weaknesses

disclosure@vulncheck.com
CWE-639

Social media

Hype score
Not currently trending