CVE-2025-61928 | better-auth Better Auth up to 1.3.25 /api/auth/api-key/create improper authorization (GHSA-99h5-pjcv-gr6v)
A vulnerability identified as critical has been detected in better-auth Better Auth up to 1.3.25. This affects an unknown function of the file /api/auth/api-key/create. Performing manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2025-61928. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.