@better-auth/sso vulnerabilities
CVEs whose affected-version data names the @better-auth/sso package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-53515High· 7.1@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
▾ Twilightbetter-auth · @better-auth/ssoEPSS 0.43%via GHSA
CVE-2026-53513Critical· 9.6@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
▾ Midnightbetter-auth · @better-auth/ssoEPSS 0.25%via GHSA