CVE-2025-71402 | better-auth up to 1.3.34 Multi-Session Plugin internalAdapter.deleteSessions _multi-* signature verification (EUVD-2025-210584)
A vulnerability was found in better-auth up to 1.3.34. It has been classified as critical. This issue affects the function internalAdapter.deleteSessions of the component Multi-Session Plugin. Performing a manipulation of the argument _multi-* results in improper verification of cryptographic signature.
This vulnerability is reported as CVE-2025-71402. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.