Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
GHSA-rjg6-39jm-rgg4Critical· 9.9@better-auth/scim: account takeover and stale access via SCIM provider-id collision
GHSA-h3rm-78g3-j7cpHigh· 7.1@better-auth/stripe: cross-organization billing tampering in organization subscription actions
GHSA-qq9h-g4jm-xgf3High· 8.3Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
CVE-2026-53515High· 7.1@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
GHSA-p2fr-6hmx-4528Medium· 6.4@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
CVE-2026-53514High· 7.7Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
CVE-2026-53516High· 8.3Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
GHSA-86j7-9j95-vpqjHigh· 7.7Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
GHSA-9h47-pqcx-hjr4High· 8.7Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
CVE-2026-53517High· 8.1Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
CVE-2026-53513Critical· 9.6@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
CVE-2026-53518High· 8.1@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
GHSA-2vg6-77g8-24mpLow· 3.8Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
GHSA-j8v8-g9cx-5qf4High· 8.3@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
CVE-2026-53512Critical· 9.1Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.