GHSA-wmjr-v86c-m9jj

Suggest an improvement
Source
https://github.com/advisories/GHSA-wmjr-v86c-m9jj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-wmjr-v86c-m9jj/GHSA-wmjr-v86c-m9jj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wmjr-v86c-m9jj
Aliases
Published
2025-11-26T22:11:50Z
Modified
2026-08-02T03:56:46Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N CVSS Calculator
Summary
Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
Details

Summary

A vulnerability was identified in the multi-session plugin for Better Auth, specifically in the /sign-out after-hook. The hook trusts raw multi-session cookies and forwards the extracted values directly to internalAdapter.deleteSessions without verifying the cookie signature. Because cookie values are not validated with getSignedCookie (or any equivalent check), an attacker can supply a forged _multi-* cookie to trigger deletion of arbitrary session tokens.

Database specific
{
    "cwe_ids":  [
        "CWE-287",
        "CWE-345"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-11-26T22:11:50Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / better-auth

Package

Affected ranges

Type
SEMVER
Events
Introduced
1.3.34
Fixed
1.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-wmjr-v86c-m9jj/GHSA-wmjr-v86c-m9jj.json"