CVE-2025-71399: Path Normalization Bypass in Better Auth
A vulnerability in Better Auth versions prior to 1.4.5 allows attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path. This issue has a CVSS score of 8.6 and is classified as HIGH severity.