Use of Web Browser Cache Containing Sensitive Information Affecting better-call package, versions <1.0.12


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-BETTERCALL-10734084
  • published13 Jul 2025
  • disclosed11 Jul 2025
  • creditmwlik

Introduced: 11 Jul 2025

CVE NOT AVAILABLE CWE-525  (opens in a new tab)

How to fix?

Upgrade better-call to version 1.0.12 or higher.

Overview

better-call is a Better call is a tiny web framework for creating endpoints that can be invoked as a normal function or mounted to a router to be served by any web standard compatible server (like Bun, node, nextjs, sveltekit...) and also includes a typed RPC client for t

Affected versions of this package are vulnerable to Use of Web Browser Cache Containing Sensitive Information via insufficient path sanitization in the request processing logic. An attacker can access sensitive user session data by crafting requests that mimic static asset paths, causing a CDN to cache and serve sensitive responses to unauthorized users.

References

CVSS Base Scores

version 4.0
version 3.1