@better-auth/scim vulnerabilities
CVEs whose affected-version data names the @better-auth/scim package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
GHSA-rjg6-39jm-rgg4Critical· 9.9@better-auth/scim: account takeover and stale access via SCIM provider-id collision
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
▾ Midnightbetter-auth · @better-auth/scimvia GHSA
GHSA-2vg6-77g8-24mpLow· 3.8Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
▾ Sunlitbetter-auth · better-authvia GHSA
GHSA-j8v8-g9cx-5qf4High· 8.3@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
▾ Twilightbetter-auth · @better-auth/scimvia GHSA